CVE-2022-0668: JFrog Artifactory

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

JFrog Artifactory prior to 7.37.13 is vulnerable to Authentication Bypass, which can lead to Privilege Escalation when a specially crafted request is sent by an unauthenticated user.

Affected products

  • JFrog Artifactory: from 6.0.0, before 6.23.41 (fixed in 6.23.41); from 7.0.0, before 7.37.13 (fixed in 7.37.13)

Published 2023-01-08. Last modified 2026-06-17.