Executive brief
JFrog Artifactory, a platform used to manage and store software building blocks, has a security flaw that allows users with limited access to view sensitive information from other projects. An attacker with basic read permissions to one repository could exploit this to steal secrets and environment settings from protected builds in different repositories. This could lead to the exposure of confidential credentials or configuration data used during the software development process.
Technical details
An information disclosure vulnerability (CWE-200) exists in JFrog Artifactory Self-Managed versions. The flaw allows a remote authenticated attacker with 'Build Reader' or general read access to an ordinary repository to select and retrieve repository parameters from other, potentially protected, builds. This occurs during the retrieval of environment properties, leading to the exposure of build environment secrets. The vulnerability is caused by insufficient isolation between repository environment properties. Patches are available in versions 7.146.34 and 7.161.15.
Affected products
- JFrog Artifactory Self-Managed 7.146.0 to 7.146.33, 7.161.0 to 7.161.14
Timeline
- 2026-07-27: advisory: JFrog published the security advisory and NVD record.
- 2026-07-27: patched: Fixed in Artifactory 7.161.15 and 7.146.34.