ARTIFACTORY: Tomcat CVEs security impact on Artifactory
Tomcat is a main component of Artifactory, with many known vulnerabilities the JFrog customers and users are concerned about.
With Artifactory updated on a regular basis with new security patches and upgrades, it is not always easy to know whether the version of Artifactory you are currently using is in fact impacted.
The goal of this article is to answer your questions regarding the security impact of high-profile Tomcat CVEs on Artifactory, following extensive research by the JFrog Application Security Team.
CVE-2022-29885 - This CVE has been found to not impact Artifactory, as it does not include the vulnerable component of this vulnerability.
CVE-2022-42252 - Does not impact Artifactory, since it does not make use of Tomcat with the vulnerable configuration.
CVE-2022-45143 - This CVE has been addressed by upgrading Tomcat to version 9.0.71. This means that Artifactory is not impacted by this CVE starting from version 7.55.2 and above.
We welcome you to refer to the official JFrog website fixed security vulnerabilities webpage, for complete details regarding many Tomcat and other component vulnerabilities, in the following link:
https://www.jfrog.com/confluence/display/JFROG/Fixed+Security+Vulnerabilities