CVE-2023-42509
MEDIUMJfrog Artifactory < 7.77.0 - Improper Exception Handling
Title source: ruleDescription
JFrog Artifactory later than version 7.17.4 but prior to version 7.77.0 is vulnerable to an issue whereby a sequence of improperly handled exceptions in repository configuration initialization steps may lead to exposure of sensitive data.
Scores
CVSS v3
6.6
EPSS
0.0027
EPSS Percentile
50.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-755
Status
published
Products (1)
jfrog/artifactory
7.17.4 - 7.77.0
Published
Mar 07, 2024
Tracked Since
Feb 18, 2026