CVE-2025-14830: JFrog Artifactory Cross-Site Scripting
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in JFrog Artifactory (Workers) allows Cross-Site Scripting (XSS).This issue affects Artifactory (Workers): from >=7.94.0 through <7.117.10.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14830?
CVE-2025-14830 is rated as a high severity vulnerability due to its potential impact on the application by allowing cross-site scripting.
How do I fix CVE-2025-14830?
To fix CVE-2025-14830, update JFrog Artifactory to version 7.117.10 or later.
What software versions are affected by CVE-2025-14830?
CVE-2025-14830 affects JFrog Artifactory versions from 7.94.0 to less than 7.117.10.
What type of vulnerability is CVE-2025-14830?
CVE-2025-14830 is classified as an improper neutralization of input during web page generation, leading to cross-site scripting (XSS).
Can CVE-2025-14830 affect users of JFrog Artifactory?
Yes, CVE-2025-14830 can affect users of JFrog Artifactory by potentially allowing attackers to execute malicious scripts in the users' browsers.