CVE-2024-3505
JFrog Self-Hosted Artifactory Proxy configuration accessible to low-privilege users
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
JFrog Artifactory Self-Hosted versions below 7.77.3, are vulnerable to sensitive information disclosure whereby a low-privileged authenticated user can read the proxy configuration.
This does not affect JFrog cloud deployments.
Las versiones autohospedadas de JFrog Artifactory inferiores a 7.77.3 son vulnerables a la divulgación de información confidencial mediante la cual un usuario autenticado con pocos privilegios puede leer la configuración del proxy. Esto no afecta las implementaciones en la nube de JFrog.
JFrog Artifactory Self-Hosted versions below 7.77.3, are vulnerable to sensitive information disclosure whereby a low-privileged authenticated user can read the proxy configuration. This does not affect JFrog cloud deployments.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2024-04-09 CVE Reserved
- 2024-04-15 CVE Published
- 2024-04-15 EPSS Updated
- 2024-08-01 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
- CAPEC-37: Retrieve Embedded Sensitive Data
References (1)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
JFrog Search vendor "JFrog" | Artifactory Self-Hosted Search vendor "JFrog" for product "Artifactory Self-Hosted" | < 7.77.3 Search vendor "JFrog" for product "Artifactory Self-Hosted" and version " < 7.77.3" | en |
Affected
|