CVE-2023-42509
MEDIUMJFrog Artifactory 7.17.4-7.77.0 - Sensitive Data Exposure via Repository Configuration Initialization
Title source: llmDescription
JFrog Artifactory later than version 7.17.4 but prior to version 7.77.0 is vulnerable to an issue whereby a sequence of improperly handled exceptions in repository configuration initialization steps may lead to exposure of sensitive data.
References (1)
Core 1
Core References
Scores
CVSS v3
6.6
EPSS
0.0044
EPSS Percentile
34.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-755
Status
published
Products (1)
jfrog/artifactory
7.17.4 - 7.77.0
Published
Mar 07, 2024
Tracked Since
Feb 18, 2026