Filtered by vendor Jfrog
Subscribe
Total
70 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-68755 | 1 Jfrog | 1 Artifactory | 2026-09-02 | N/A | 4.3 MEDIUM |
| A bundle writer may create misleading release promotion information under specific conditions. | |||||
| CVE-2026-68756 | 1 Jfrog | 1 Artifactory | 2026-09-02 | N/A | 6.6 MEDIUM |
| A party with write access to stored session data may affect JFrog Artifactory under specific conditions. | |||||
| CVE-2026-68757 | 1 Jfrog | 1 Artifactory | 2026-09-02 | N/A | 7.5 HIGH |
| A user with access to a valid SAML response may impersonate another user under specific conditions. | |||||
| CVE-2026-68760 | 1 Jfrog | 1 Artifactory | 2026-09-02 | N/A | 5.3 MEDIUM |
| An unauthenticated user may bypass authentication under specific cache conditions. | |||||
| CVE-2026-68758 | 1 Jfrog | 1 Artifactory | 2026-09-02 | N/A | 6.5 MEDIUM |
| A low-privileged authenticated user may access restricted support information under specific conditions. | |||||
| CVE-2026-68759 | 1 Jfrog | 1 Artifactory | 2026-09-02 | N/A | 7.2 HIGH |
| A holder of a valid integration credential may impersonate other users under specific conditions. | |||||
| CVE-2026-66384 | 1 Jfrog | 1 Artifactory | 2026-08-28 | N/A | 5.3 MEDIUM |
| An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions. | |||||
| CVE-2026-65921 | 1 Jfrog | 1 Artifactory | 2026-07-30 | N/A | 8.8 HIGH |
| A path validation weakness in archive extraction/write handling allows entries with traversal sequences to be written outside the intended build artifacts location. | |||||
| CVE-2026-65618 | 1 Jfrog | 1 Artifactory | 2026-07-30 | N/A | 6.5 MEDIUM |
| Improper URL validation when handling specific URLs, allows an attacker, under certain conditions, to make unauthorized requests from JFrog Artifactory, potentially exposing internal services and cached response data. | |||||
| CVE-2026-65617 | 1 Jfrog | 1 Artifactory | 2026-07-30 | N/A | 8.8 HIGH |
| A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact confidentiality, integrity, and availability under specific repository conditions. | |||||
| CVE-2026-65616 | 1 Jfrog | 1 Artifactory | 2026-07-30 | N/A | 8.8 HIGH |
| Incorrect authorization validation in refresh token signature allows non-admin users to obtain a signed JFrog administrator token. | |||||
| CVE-2026-66018 | 1 Jfrog | 1 Artifactory | 2026-07-30 | N/A | 6.5 MEDIUM |
| Build readers can access another repository's environment properties. A caller with read access to an ordinary repository can select a readable repository parameter while retrieving environment properties for a protected build, exposing build environment secrets (confidentiality impact; no integrity or availability impact demonstrated). | |||||
| CVE-2026-66015 | 1 Jfrog | 1 Artifactory | 2026-07-30 | N/A | 7.2 HIGH |
| An authenticated privilege-escalation vulnerability in JFrog Platform may be exploited under admin-provisioned account conditions. Successful exploitation may grant temporary platform administrator access. | |||||
| CVE-2026-65925 | 1 Jfrog | 1 Artifactory | 2026-07-30 | N/A | 6.5 MEDIUM |
| A user with JFrog Artifactory Cargo remote repository read access could make Artifactory request unintended URLs and return the response. | |||||
| CVE-2026-65924 | 1 Jfrog | 1 Artifactory | 2026-07-30 | N/A | 6.5 MEDIUM |
| JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Server-Side Request Forgery (SSRF). An authenticated user - or, if anonymous access is enabled on the repository, an unauthenticated user - could cause Artifactory to issue outbound HTTP requests to arbitrary destinations and receive the response content. | |||||
| CVE-2026-65923 | 1 Jfrog | 1 Artifactory | 2026-07-30 | N/A | 6.8 MEDIUM |
| A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user, under specific repository access conditions, to cause unintended server-side requests. The issue primarily affects confidentiality and integrity and has been addressed in fixed Artifactory versions. | |||||
| CVE-2026-65922 | 1 Jfrog | 1 Artifactory | 2026-07-30 | N/A | 7.1 HIGH |
| An authorization weakness in JFrog Artifactory internal metadata handling could allow a user with limited repository access to write to restricted internal metadata areas under specific conditions. Successful abuse is limited to integrity and availability impact at a low level; confidentiality is not affected. | |||||
| CVE-2026-42017 | 1 Jfrog | 1 Artifactory | 2026-07-30 | N/A | 8.8 HIGH |
| An event-handling weakness in JFrog Artifactory could expose privileged authorization material to a lower-privileged user under specific conditions. | |||||
| CVE-2024-3505 | 1 Jfrog | 1 Artifactory | 2026-06-17 | N/A | 4.3 MEDIUM |
| JFrog Artifactory Self-Hosted versions below 7.77.3, are vulnerable to sensitive information disclosure whereby a low-privileged authenticated user can read the proxy configuration. This does not affect JFrog cloud deployments. | |||||
| CVE-2024-2247 | 1 Jfrog | 1 Artifactory | 2026-06-17 | N/A | 8.8 HIGH |
| JFrog Artifactory versions below 7.77.7, 7.82.1, are vulnerable to DOM-based cross-site scripting due to improper handling of the import override mechanism. | |||||
