CVE-2024-4142

CRITICAL

JFrog Artifactory - Privilege Escalation

Title source: llm
STIX 2.1

Description

An Improper input validation vulnerability that could potentially lead to privilege escalation was discovered in JFrog Artifactory. Due to this vulnerability, users with low privileges may gain administrative access to the system. This issue can also be exploited in Artifactory platforms with anonymous access enabled.

References (1)

Core 1

Scores

CVSS v3 9.0
EPSS 0.0067
EPSS Percentile 47.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-20
Status published
Products (7)
JFrog/Artifactory < 7.55.17
JFrog/Artifactory < 7.59.22
JFrog/Artifactory < 7.63.21
JFrog/Artifactory < 7.68.21
JFrog/Artifactory < 7.71.21
JFrog/Artifactory < 7.77.11
JFrog/Artifactory < 7.84.6
Published May 01, 2024
Tracked Since Feb 18, 2026