CVE-2023-42509
CVE-2023-42509 is a medium-severity vulnerability in Jfrog Artifactory with a CVSS 3.x base score of 6.6. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-755.
Key facts
- Severity: Medium (CVSS 3.x base score 6.6)
- EPSS exploit prediction: 0% (36th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2023-46942
- Weakness: CWE-755
- Affected product: Jfrog Artifactory
- Published:
- Last modified:
Description
JFrog Artifactory later than version 7.17.4 but prior to version 7.77.0 is vulnerable to an issue whereby a sequence of improperly handled exceptions in repository configuration initialization steps may lead to exposure of sensitive data.
Frequently asked questions
- What is CVE-2023-42509?
- JFrog Artifactory later than version 7.17.4 but prior to version 7.77.0 is vulnerable to an issue whereby a sequence of improperly handled exceptions in repository configuration initialization steps may lead to exposure of sensitive data.
- How severe is CVE-2023-42509?
- CVE-2023-42509 has a CVSS 3.x base score of 6.6, rated medium severity. It is exploitable over network with high attack complexity, requires high privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2023-42509 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (36th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2023-42509?
- CVE-2023-42509 affects Jfrog Artifactory. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2023-42509?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2023-42509 have an EU (EUVD) identifier?
- Yes. CVE-2023-42509 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2023-46942.
- When was CVE-2023-42509 published?
- CVE-2023-42509 was published on 2024-03-07 and last updated on 2026-06-17.
References
Affected products (1)
- cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*
More vulnerabilities in Jfrog Artifactory
- CVE-2026-82329 — Critical (CVSS 9.8): JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated…
- CVE-2019-17444 — Critical (CVSS 9.8): Jfrog Artifactory uses default passwords (such as "password") for administrative accounts and does not require users to…
- CVE-2018-19971 — Critical (CVSS 9.8): JFrog Artifactory Pro 6.5.9 has Incorrect Access Control.
- CVE-2019-9733 — Critical (CVSS 9.8): An issue was discovered in JFrog Artifactory 6.7.3. By default, the access-admin account is used to reset the password…
- CVE-2016-10036 — Critical (CVSS 9.8): Unrestricted file upload vulnerability in ui/artifact/upload in JFrog Artifactory before 4.16 allows remote attackers…
- CVE-2016-6501 — Critical (CVSS 9.8): JFrog Artifactory before 4.11 allows remote attackers to execute arbitrary code via an LDAP attribute with a crafted…
All CVEs affecting Jfrog Artifactory →
Other CWE-755 (Improper Handling of Exceptional Conditions) vulnerabilities
- CVE-2025-34193 — Critical (CVSS 9.8): Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 25.1.102 and Application versions prior…
- CVE-2025-10156 — Critical (CVSS 9.8): An Improper Handling of Exceptional Conditions vulnerability in the ZIP archive scanning component of mmaitre314…
- CVE-2022-48673 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: net/smc: Fix possible access to freed memory in…
- CVE-2024-26584 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: net: tls: handle backlogging of crypto…
- CVE-2021-42142 — Critical (CVSS 9.8): An issue was discovered in Contiki-NG tinyDTLS through master branch 53a0d97. DTLS servers mishandle the early use of a…
- CVE-2021-42141 — Critical (CVSS 9.8): An issue was discovered in Contiki-NG tinyDTLS through 2018-08-30. One incorrect handshake could complete with…
Browse all CWE-755 (Improper Handling of Exceptional Conditions) vulnerabilities →