Vulnerabilities (CVE)

Filtered by vendor Jfrog Subscribe
Total 70 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-68755 1 Jfrog 1 Artifactory 2026-09-02 N/A 4.3 MEDIUM
A bundle writer may create misleading release promotion information under specific conditions.
CVE-2026-68756 1 Jfrog 1 Artifactory 2026-09-02 N/A 6.6 MEDIUM
A party with write access to stored session data may affect JFrog Artifactory under specific conditions.
CVE-2026-68757 1 Jfrog 1 Artifactory 2026-09-02 N/A 7.5 HIGH
A user with access to a valid SAML response may impersonate another user under specific conditions.
CVE-2026-68760 1 Jfrog 1 Artifactory 2026-09-02 N/A 5.3 MEDIUM
An unauthenticated user may bypass authentication under specific cache conditions.
CVE-2026-68758 1 Jfrog 1 Artifactory 2026-09-02 N/A 6.5 MEDIUM
A low-privileged authenticated user may access restricted support information under specific conditions.
CVE-2026-68759 1 Jfrog 1 Artifactory 2026-09-02 N/A 7.2 HIGH
A holder of a valid integration credential may impersonate other users under specific conditions.
CVE-2026-66384 1 Jfrog 1 Artifactory 2026-08-28 N/A 5.3 MEDIUM
An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.
CVE-2026-65921 1 Jfrog 1 Artifactory 2026-07-30 N/A 8.8 HIGH
A path validation weakness in archive extraction/write handling allows entries with traversal sequences to be written outside the intended build artifacts location.
CVE-2026-65618 1 Jfrog 1 Artifactory 2026-07-30 N/A 6.5 MEDIUM
Improper URL validation when handling specific URLs, allows an attacker, under certain conditions, to make unauthorized requests from JFrog Artifactory, potentially exposing internal services and cached response data.
CVE-2026-65617 1 Jfrog 1 Artifactory 2026-07-30 N/A 8.8 HIGH
A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact confidentiality, integrity, and availability under specific repository conditions.
CVE-2026-65616 1 Jfrog 1 Artifactory 2026-07-30 N/A 8.8 HIGH
Incorrect authorization validation in refresh token signature allows non-admin users to obtain a signed JFrog administrator token.
CVE-2026-66018 1 Jfrog 1 Artifactory 2026-07-30 N/A 6.5 MEDIUM
Build readers can access another repository's environment properties. A caller with read access to an ordinary repository can select a readable repository parameter while retrieving environment properties for a protected build, exposing build environment secrets (confidentiality impact; no integrity or availability impact demonstrated).
CVE-2026-66015 1 Jfrog 1 Artifactory 2026-07-30 N/A 7.2 HIGH
An authenticated privilege-escalation vulnerability in JFrog Platform may be exploited under admin-provisioned account conditions. Successful exploitation may grant temporary platform administrator access.
CVE-2026-65925 1 Jfrog 1 Artifactory 2026-07-30 N/A 6.5 MEDIUM
A user with JFrog Artifactory Cargo remote repository read access could make Artifactory request unintended URLs and return the response.
CVE-2026-65924 1 Jfrog 1 Artifactory 2026-07-30 N/A 6.5 MEDIUM
JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Server-Side Request Forgery (SSRF). An authenticated user - or, if anonymous access is enabled on the repository, an unauthenticated user - could cause Artifactory to issue outbound HTTP requests to arbitrary destinations and receive the response content.
CVE-2026-65923 1 Jfrog 1 Artifactory 2026-07-30 N/A 6.8 MEDIUM
A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user, under specific repository access conditions, to cause unintended server-side requests. The issue primarily affects confidentiality and integrity and has been addressed in fixed Artifactory versions.
CVE-2026-65922 1 Jfrog 1 Artifactory 2026-07-30 N/A 7.1 HIGH
An authorization weakness in JFrog Artifactory internal metadata handling could allow a user with limited repository access to write to restricted internal metadata areas under specific conditions. Successful abuse is limited to integrity and availability impact at a low level; confidentiality is not affected.
CVE-2026-42017 1 Jfrog 1 Artifactory 2026-07-30 N/A 8.8 HIGH
An event-handling weakness in JFrog Artifactory could expose privileged authorization material to a lower-privileged user under specific conditions.
CVE-2024-3505 1 Jfrog 1 Artifactory 2026-06-17 N/A 4.3 MEDIUM
JFrog Artifactory Self-Hosted versions below 7.77.3, are vulnerable to sensitive information disclosure whereby a low-privileged authenticated user can read the proxy configuration. This does not affect JFrog cloud deployments.
CVE-2024-2247 1 Jfrog 1 Artifactory 2026-06-17 N/A 8.8 HIGH
JFrog Artifactory versions below 7.77.7, 7.82.1, are vulnerable to DOM-based cross-site scripting due to improper handling of the import override mechanism.