PT-2024-26298 · Jfrog · Jfrog Artifactory

Published

2024-04-15

·

Updated

2025-04-02

·

CVE-2024-3505

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions JFrog Artifactory Self-Hosted versions prior to 7.77.3
Description The issue allows a low-privileged authenticated user to disclose sensitive information by reading the proxy configuration. This does not affect JFrog cloud deployments.
Recommendations For versions prior to 7.77.3, update to version 7.77.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the proxy configuration to minimize the risk of exploitation.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

BIT-ARTIFACTORY-2024-3505
CVE-2024-3505

Affected Products

Jfrog Artifactory