SB2026083198 - Input validation error in JFrog Artifactory
Published: August 31, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Input validation error (CVE-ID: CVE-2024-2248)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to take over the end user's account.
The vulnerability exists due to improper input validation in URL handling when processing a specially crafted URL sent to the victim by email. A remote attacker can send a specially crafted URL to the victim to take over the end user's account.
User interaction is required to click the crafted URL delivered by email.
Remediation
Install update from vendor's website.