CVE-2024-4142: JFrog Artifactory
Critical severity, CVSS 9.0. EPSS: 0.7% chance of exploitation in the next 30 days.
An Improper input validation vulnerability that could potentially lead to privilege escalation was discovered in JFrog Artifactory. Due to this vulnerability, users with low privileges may gain administrative access to the system. This issue can also be exploited in Artifactory platforms with anonymous access enabled.
Affected products
- JFrog Artifactory: before 7.84.6 (fixed in 7.84.6); before 7.77.11 (fixed in 7.77.11); before 7.71.21 (fixed in 7.71.21); before 7.68.21 (fixed in 7.68.21); before 7.63.21 (fixed in 7.63.21); before 7.59.22 (fixed in 7.59.22); …
Published 2024-05-01. Last modified 2026-06-17.