Distribution Fixed Security Vulnerabilities

Fixed security vulnerabilities for JFrog Distribution are described in the following topics.

CVEs Impacting Distribution

The following is a list of CVEs that impact Distribution.

CVESeverityDistribution Fix VersionFix Description
CVE-2025-49844HighTBDPackage being upgraded. CVE requires an authenticated user to be exploited
CVE-2025-48924Medium2.33.0Upgraded Apache Commons Lang to a fixed version.
CVE-2025-48988High2.31.2Upgraded Apache Tomcat to a fixed version.
CVE-2025-46701High2.31.1Upgraded Apache Tomcat to a fixed version.
CVE-2025-24813Critical2.30.0Upgraded Apache Tomcat to a fixed version.
CVE-2024-50379High2.29.1Upgraded Apache Tomcat to a fixed version.
CVE-2024-45338High2.29.1Upgraded Golang to a fixed version.
CVE-2024-38827Medium2.29.1Upgraded Spring Security to a fixed version.

CVE-2024-12798

CVE-2024-12801

Medium2.29.1Upgraded logback-core to a fixed version.
CVE-2024-38996High2.28.1Upgraded ag-grid-community and ag-grid-enterprise due to a prototype pollution via the _.mergeDeep function.

CVE-2023-50387

CVE-2023-50868

CVE-2024-25638

High2.27.2Upgraded java_commons to a fixed version.
CVE-2024-39321High2.27.2Upgraded Traefik to a fixed version due to a vulnerability that allows the bypassing of IP allow-lists.
CVE-2204-30172Medium2.26.1Upgraded Bouncy Castle to a fixed version because of an issue discovered in Java Cryptography APIs.
CVE-2024-30171Medium2.26.1Upgraded Bouncy Castle to a fixed version because of an issue discovered in Java TLS API and JSSE Provider.
CVE-2024-29857Medium2.26.1Upgraded Bouncy Castle to a fixed version because of an issue discovered in ECCurve.java and ECCurve.cs.
CVE-2024-22259High2.24.0Upgraded Spring Framework to a fixed version.
CVE-2024-1597Critical2.23.0Upgraded pgjdbc to a fixed version.
CVE-2024-22233High2.23.0Upgraded Spring Framework to a fixed version.
CVE-2024-22243High2.23.0Upgraded UriComponentsBuilder to a fixed version.

CVE-2024-26308

CVE-2024-25710

Medium2.23.0Upgraded Apache Commons Compress to a fixed version.
CVE-2023-50570Medium2.23.0Upgraded IPAddress to a fixed version.
CVE-2023-47633High2.22.1Upgraded Traefik to a fixed version.
CVE-2023-46589High2.22.1Upgraded Apache Tomcat to a fixed version.
CVE-2023-6378High2.22.1Upgraded logback to a fixed version.
CVE-2023-4586High2.21.3Upgraded the Hot Rod client to a fixed version.
CVE-2023-35116Medium2.21.3Upgraded jackson-databind to a fixed version.
CVE-2023-41080Medium2.21.3Upgraded Apache Tomcat to a fixed version.
CVE-2023-34035Medium2.21.3Upgraded Spring Framework to a fixed version.
CVE-2022-48345Medium2.19.1Upgraded sanitize-url to a fixed version.

CVEs Not Impacting Distribution

The following is a list of CVEs that do not impact Distribution.

CVESeverityDistribution Fix VersionReason
CVE-2025-53864Medium2.33.0Upgraded Connect2id Nimbus JOSE + JWT to a fixed version.
CVE-2025-31651Critical2.30.1Upgraded Apache Tomcat to a fixed version.
CVE-2025-27820High2.30.1Upgraded Apache HttpClient to a fixed version.
CVE-2025-25193Medium2.30.0Upgraded Netty to a fixed version.

CVE-2025-24970

CVE-2024-47535

Medium2.29.1Upgraded Netty to a fixed version.
CVE-2021-23566Medium2.28.1Upgraded nanoid to a fixed version.
CVE-2024-47554High2.28.1Does not affect Distribution as the vulnerable commons functionality is not in use.
CVE-2024-47535Medium2.28.1Upgraded Netty to a fixed version.
CVE-2024-38821Critical2.28.1Upgraded Spring Security to a fixed version.
CVE-2024-38820Medium2.28.1Upgraded DataBinder to a fixed version.
CVE-2024-38819High2.28.1Upgraded Spring Framework to a fixed version due to a vulnerability to path traversal attacks.
CVE-2024-7254High2.28.1Upgraded Protobuf to a fixed version.
CVE-2024-38816High2.27.2Upgraded Spring Framework to a fixed version due to a vulnerability to path traversal attacks.
CVE-2024-24790Critical2.27.2Upgraded observability to a fixed version.
CVE-2024-21634High2.26.1Upgraded Amazon Ion to a fixed version.
CVE-2024-22262High2.25.1Upgraded Spring Framework to a fixed version.
CVE-2023-33202Medium2.24.0Upgraded Bouncy Castle to a fixed version.
CVE-2024-29025Medium2.24.0Upgraded Netty to a fixed version.
CVE-2204-22257High2.24.0Upgraded Spring Security to a fixed version.
CVE-2023-34462Medium2.21.3Upgraded netty-handler to a fixed version.
CVE-2023-44487High2.21.3Upgraded netty-codec-http2 to a fixed version.
CVE-2023-34462Medium2.20.2Upgraded Netty to a fixed version.
CVE-2023-2976High2.20.1Upgraded Google Guava to a fixed version.
CVE-2023-34104High2.19.1Upgraded fast-xml-parser to a fixed version.
CVE-2023-20859Medium2.19.1Upgraded Spring Vault core to a fixed version.
CVE-2023-1370High2.18.1Upgraded to a fixed version.
CVE-2022-1471Medium2.18.1Upgraded the SnakeYAML library to a fixed version.
CVE-2023-20873Critical2.18.1Upgraded Spring Boot to a fixed version.
CVE-2023-20863Medium2.18.1Upgraded Spring Framework to a fixed version.
CVE-2023-20862Critical2.18.1Upgraded Spring Security to a fixed version.
CVE-2023-20860High2.18.1Upgraded to a fixed version.
CVE-2022-45868HighN/AThis dependency is used in the development process only and does not impact the final product.
CVE-2022-41915MediumN/AUpgraded to a fixed version.
CVE-2022-45143HighN/ADistribution doesn’t use the API related to this vulnerability.
CVE-2022-38900HighN/AUpdated the UI common library.
CVE-2022-21222HighN/AThis dependency is used in the development process only and is not included in the final product deployment.
CVE-2022-45143HighN/ADistribution does not use the vulnerable API.
CVE-2022-41946MediumN/AUpdating the drivers to 42.5.1 fixed the vulnerability.
CVE-2022-42889CriticalN/AUpgraded to a fixed version, although Distribution does not use the vulnerable API.
CVE-2022-31692CriticalN/AUpgraded to a fixed version.
CVE-2022-3171HighN/AUpgraded to a fixed version.
CVE-2022-42004HighN/AUpgraded to a fixed version.
CVE-2022-38750MediumN/AUpgraded to a fixed version.
CVE-2022-38749MediumN/AUpgraded to a fixed version.
CVE-2022-1471CriticalN/ADoes not affect Distribution since Distribution does not use the potentially-harmful constructor.
CVE-2022-42252HighN/ADoes not affect Distribution since the product uses Tomcat version 9.0.58 and doesn’t redefine rejectIllegalHeader, so its effective value is “true“ (default).
CVE-2016-1000027CriticalN/ADoes not affect Distribution since Distribution is not using the vulnerable API.
CVE-2022-22978HighN/AUpgraded spring-security-web to version 5.7.0.
CVE-2022-22968MediumN/AUpgraded spring-context to version 5.3.21.
CVE-2022-22970MediumN/AUpgraded spring-beans to version 5.3.21.
CVE-2021-21309CriticalN/ADoes not affect Distribution, since Distribution uses 64-bit Redis and the issue affects only on a 32-bit system or as a 32-bit Redis executable running on a 64-bit system.
CVE-2022-24785High2.12.3Moment.js is a JavaScript date library for parsing, validating, manipulating, and formatting dates. A path traversal vulnerability impacts npm (server) users of Moment.js between versions 1.0.1 and 2.29.1, especially if a user-provided locale string is directly used to switch moment locale. This problem is patched in 2.29.2, and the patch can be applied to all affected versions. As a workaround, sanitize the user-provided locale name before passing it to Moment.js.
CVE-2022-21724Medium2.12.0pgjdbc, the official PostgreSQL JDBC Driver, has been upgraded to version 42.2.25.
CVE-2021-42550Medium2.11.0Upgraded the logback.xml to version 1.2.9.
CVE-2022-24823MediumN/ADoes not affect Distribution, since the vulnerability only impacts applications running on Java version 6 and lower.

Did this page help you?