CVE-2024-3505: JFrog Artifactory

Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.

JFrog Artifactory Self-Hosted versions below 7.77.3, are vulnerable to sensitive information disclosure whereby a low-privileged authenticated user can read the proxy configuration. This does not affect JFrog cloud deployments.

Affected products

  • JFrog Artifactory: before 7.77.3 (fixed in 7.77.3)

Published 2024-04-15. Last modified 2026-06-17.