Home » Database

AVID-2026-R1595

Description

JFrog Artifactory Cache Poisoning (CVE-2024-6915)

Details

JFrog Artifactory versions below 7.90.6, 7.84.20, 7.77.14, 7.71.23, 7.68.22, 7.63.22, 7.59.23, 7.55.18 are vulnerable to Improper Input Validation that could potentially lead to cache poisoning.

Reason for inclusion in AVID: CVE-2024-6915 describes a cache poisoning vulnerability in JFrog Artifactory due to improper input validation. Artifactory is a widely used artifact repository in software supply chains, including those used for AI/ML pipelines (dependency registries, containers, etc.). A successful cache poisoning could compromise the integrity of artifacts (models, dependencies, containers) distributed and consumed during building, training, deploying, or serving AI systems. Given this directly affects software supply chain components that general-purpose AI systems rely on, it qualifies as a security vulnerability impacting the AI supply chain. The report cites authoritative sources (NVD entry and vendor advisories) confirming the issue and its risk.

References

Affected or Relevant Artifacts

  • Developer: JFrog
  • Deployer: JFrog
  • Artifact Details:
TypeName
SystemArtifactory

Impact

AVID Taxonomy Categorization

  • Risk domains: Security
  • SEP subcategories: S0100: Software Vulnerability
  • Lifecycle stages: L06: Deployment

CVSS

Version3.1
Vector StringCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:L
Base Score9.3
Base Severity🔴 Critical
Attack VectorNETWORK
Attack Complexity🟢 Low
Privileges RequiredNONE
User InteractionNONE
ScopeCHANGED
Confidentiality ImpactNONE
Integrity Impact🔴 High
Availability Impact🟢 Low

CWE

IDDescription
CWE-20CWE-20 Improper Input Validation

Other information

  • Report Type: Advisory
  • Credits:
  • Date Reported: 2024-08-05
  • Version: 0.3.3
  • AVID Entry