CVE-2022-0668: JFrog Artifactory
Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.
JFrog Artifactory prior to 7.37.13 is vulnerable to Authentication Bypass, which can lead to Privilege Escalation when a specially crafted request is sent by an unauthenticated user.
Affected products
- JFrog Artifactory: from 6.0.0, before 6.23.41 (fixed in 6.23.41); from 7.0.0, before 7.37.13 (fixed in 7.37.13)
Published 2023-01-08. Last modified 2026-06-17.