QID 731272
Date Published: 2024-03-20
QID 731272: JFrog Artifactory Sensitive Information Disclosure Vulnerability (CVE-2023-42509)
JFrog Artifactory is the Universal Repository Manager supporting all major packaging formats, build tools and CI servers.
JFrog Artifactory later than version 7.17.4 but prior to version 7.77.0 is vulnerable to an issue whereby a sequence of improperly handled exceptions in repository configuration initialization steps may lead to exposure of sensitive data.
Affected Versions:
JFrog Artifactory versions from 7.17.4 prior to 7.77.0
QID Detection Logic:
Unauthenticated: This QID checks for the version of Artifactory on the target using Server Header in response.
Successful exploitation of this vulnerability may lead to exposure of sensitive data.
Solution
Customers are advised to upgrade to JFrog Artifactory 7.77.3 or higher . Please refer to JFrog Security Advisory for further updates.
Vendor References
- JFrog Artifactory Security Advisory -
jfrog.com/help/r/jfrog-release-information/cve-2023-42509-jfrog-artifactory-sensitive-data-leakage-in-repository-configuration-process
CVEs related to QID 731272
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| JFrog Artifactory Security Advisory |
|