Vulnerability Description
JFrog Artifactory Self-Hosted versions below 7.77.3, are vulnerable to sensitive information disclosure whereby a low-privileged authenticated user can read the proxy configuration. This does not affect JFrog cloud deployments.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jfrog | Artifactory | < 7.77.3 |
Related Weaknesses (CWE)
References
- https://jfrog.com/help/r/jfrog-release-information/jfrog-security-advisoriesVendor Advisory
- https://jfrog.com/help/r/jfrog-release-information/jfrog-security-advisoriesVendor Advisory
FAQ
What is CVE-2024-3505?
CVE-2024-3505 is a vulnerability with a CVSS score of 4.3 (MEDIUM). JFrog Artifactory Self-Hosted versions below 7.77.3, are vulnerable to sensitive information disclosure whereby a low-privileged authenticated user can read the proxy configuration. This does not affe...
How severe is CVE-2024-3505?
CVE-2024-3505 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-3505?
Check the references section above for vendor advisories and patch information. Affected products include: Jfrog Artifactory.