Information disclosure in JFrog Artifactory - CVE-2024-3505
Published: August 31, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in proxy configuration when handling authenticated access to configuration data. A remote user can read the proxy configuration to disclose sensitive information.
This issue affects self-hosted deployments only.