Input validation error in JFrog Artifactory - CVE-2024-2248

 

Input validation error in JFrog Artifactory - CVE-2024-2248

Published: August 31, 2026


Vulnerability identifier: #VU146507
CSH Severity: Medium
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-2248
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to take over the end user's account.

The vulnerability exists due to improper input validation in URL handling when processing a specially crafted URL sent to the victim by email. A remote attacker can send a specially crafted URL to the victim to take over the end user's account.

User interaction is required to click the crafted URL delivered by email.


Affected software

JFrog Artifactory

How to mitigate CVE-2024-2248

Install security update from vendor's website.

JFrog Artifactory - update to 7.84.7

External References

Related Security Bulletins