What happened
JFrog Artifactory contains an improper authentication vulnerability that under default configuration can allow an unauthenticated attacker with network access to obtain administrative privileges.
Affected versions
Artifactory: before 7.111.21 (custom); 7.117.0 through before 7.117.28 (custom); 7.125.0 through before 7.125.20 (custom); 7.133.0 through before 7.133.29 (custom); 7.146.0 through before 7.146.38 (custom); 7.161.0 through before 7.161.20 (custom) Fixed: See vendor advisory.
Why it matters
This source correlation may provide earlier visibility while structured CVE metadata is still being updated.
Detection & mitigation
- Review the original advisory and validate affected versions.
- Apply vendor-provided updates or mitigations when available.