{"api_version":"v1","generated_at":"2026-10-08T20:00:00+00:00","product":{"cve_count":8,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-jfrog-jfrog-artifactory-71eae724b6d5","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"JFrog Artifactory","next_cursor":null,"observations":[{"affected":"JFrog Artifactory versions before 7.x < 7.37.13; JFrog Artifactory versions before 6.x < 6.23.41","affected_versions_present":true,"cve_id":"CVE-2022-0668","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-0668","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-09T13:44:13.635Z","patch_url":"https://www.jfrog.com/confluence/display/JFROG/CVE-2022-0668%3A+Artifactory+Authentication+Bypass","primary_source":"","published":"2023-01-08T00:00:00.000Z"},{"affected":"JFrog Artifactory versions before 7.33.6 < 7.x; JFrog Artifactory versions before 6.23.38 < 6.x","affected_versions_present":true,"cve_id":"CVE-2021-23163","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-23163","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-03T19:05:54.566Z","patch_url":"https://www.jfrog.com/confluence/display/JFROG/CVE-2021-23163%3A++Cross-Site+Request+Forgery+on+REST+using+Basic+Auth","primary_source":"","published":"2022-07-06T09:45:12.000Z"},{"affected":"JFrog Artifactory versions before 7.31.10 < 7.x; JFrog Artifactory versions before 6.23.38 < 6.x","affected_versions_present":true,"cve_id":"CVE-2021-46687","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-46687","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-04T05:17:41.514Z","patch_url":"https://www.jfrog.com/confluence/display/JFROG/CVE-2021-46687%3A+Sensitive+data+exposure+on+proxy+endpoint+for+Project+Admin","primary_source":"","published":"2022-07-06T09:35:11.000Z"},{"affected":"JFrog Artifactory versions before 7.36.1 < 7.29.8; JFrog Artifactory versions before 6.23.41 < 6.23.38","affected_versions_present":true,"cve_id":"CVE-2021-45721","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-45721","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-04T04:47:02.005Z","patch_url":"https://www.jfrog.com/confluence/display/JFROG/CVE-2021-45721%3A+Cross-Site+Script+%28XSS%29+on+User+REST+API","primary_source":"","published":"2022-07-06T09:15:11.000Z"},{"affected":"JFrog Artifactory versions before 7.36.1 < 7.36.1; JFrog Artifactory versions before 6.23.41 < 6.23.41","affected_versions_present":true,"cve_id":"CVE-2022-0573","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-0573","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-02T23:32:46.384Z","patch_url":"https://www.jfrog.com/confluence/display/JFROG/CVE-2022-0573%3A+Artifactory+Vulnerable+to+Deserialization+of+Untrusted+Data","primary_source":"","published":"2022-05-16T14:32:04.000Z"},{"affected":"JFrog Artifactory versions before 7.31.10 < 7.31.10","affected_versions_present":true,"cve_id":"CVE-2021-46270","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-46270","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-08-04T05:02:10.903Z","patch_url":"","primary_source":"","published":"2022-03-02T21:20:12.000Z"},{"affected":"JFrog Artifactory versions before 7.29.3 < 7.29.3; JFrog Artifactory versions before 6.23.38 < 6.23.38","affected_versions_present":true,"cve_id":"CVE-2021-45074","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-45074","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-08-04T04:32:13.616Z","patch_url":"","primary_source":"","published":"2022-03-02T21:20:11.000Z"},{"affected":"JFrog Artifactory versions before 7.25.4 with E+ license < 7.25.4; JFrog Artifactory versions before 6.23.30 with E+ license < 6.23.30","affected_versions_present":true,"cve_id":"CVE-2021-3860","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-3860","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-11-18T19:58:54.966Z","patch_url":"https://www.jfrog.com/confluence/display/JFROG/CVE-2021-3860%3A+Artifactory+Low+Privileged+Blind+SQL+Injection","primary_source":"","published":"2021-12-20T00:00:00.000Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"JFrog"}}
