First published: Mon Apr 15 2024(Updated: )
JFrog Artifactory Self-Hosted versions below 7.77.3, are vulnerable to sensitive information disclosure whereby a low-privileged authenticated user can read the proxy configuration. This does not affect JFrog cloud deployments.
Credit: reefs@jfrog.com
Affected Software | Affected Version | How to fix |
---|---|---|
JFrog Artifactory | <7.77.3 | |
JFrog Artifactory | <7.77.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-3505 is considered a medium severity vulnerability due to the potential for sensitive information disclosure.
To mitigate CVE-2024-3505, upgrade JFrog Artifactory to version 7.77.3 or later.
CVE-2024-3505 affects self-hosted versions of JFrog Artifactory prior to 7.77.3.
CVE-2024-3505 allows a low-privileged authenticated user to read the proxy configuration.
No, CVE-2024-3505 does not affect JFrog cloud deployments.