← Browse

Jfrog

42 CVEs
CVE IDSeverityProduct / summaryPublished
CVE-2026-69104 HIGH 7.6 Artifactory — An authenticated user may initiate repository migration operations without required repository permissions, po… 2026-08-25 CVE-2026-70548 LOW 3.5 Artifactory — Under specific circumstances, low-level user can run request to remote CocoaPods repos via JFrog Artifactory E… 2026-08-25 CVE-2026-70550 MEDIUM 6.5 Artifactory — An authorization weakness in JFrog Artifactory Composer repository handling may allow an authenticated user, u… 2026-08-25 CVE-2026-70551 HIGH 8.5 Artifactory — A user who can read an existing remote VCS repository can replace its configured origin or supply an absolute … 2026-08-25 CVE-2026-42018 HIGH 7.5 Artifactory — JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous ac… 2026-08-12 CVE-2026-65926 LOW 3.1 Artifactory — An anonymous caller when anonymous access is enabled, or a low-privilege authenticated user, may learn private… 2026-08-12 CVE-2026-66016 MEDIUM 6.7 Artifactory — Under specific self-hosted Helm configurations, generated TLS private keys may be retained in rendered manifes… 2026-08-12 CVE-2026-66375 HIGH 8.1 Artifactory — A low-privilege authenticated user may permanently remove protected internal metadata across repositories unde… 2026-08-12 CVE-2026-66376 MEDIUM 4.2 Artifactory — Credentials for a deleted user may remain valid for a short period under specific conditions. 2026-08-12 CVE-2026-66377 MEDIUM 5.3 Artifactory — An unauthenticated user may access restricted repository information under specific conditions. 2026-08-12 CVE-2026-66378 MEDIUM 4.3 Artifactory — An authenticated user without repository read permission may access private NuGet metadata under specific cond… 2026-08-12 CVE-2026-66379 MEDIUM 4.3 Artifactory — An authenticated user may view private Puppet module metadata without repository read access. 2026-08-12 CVE-2026-66380 MEDIUM 4.3 Artifactory — An authenticated user without repository read permission may access private OCI referrer metadata under specif… 2026-08-12 CVE-2026-66381 MEDIUM 5.3 Artifactory — A repository reader with cache-deploy permission may access content outside a configured upstream path under s… 2026-08-12 CVE-2026-66382 MEDIUM 4.3 Artifactory — An authenticated user may write files outside the intended Artifactory work directory under specific condition… 2026-08-12 CVE-2026-66384 MEDIUM 5.3 Artifactory — An authenticated user may write data outside the intended Docker cache path under specific remote-repository c…● exploited 2026-08-12 CVE-2026-68752 HIGH 7.2 Artifactory — A Project Resource Manager may gain broader administrative privileges under specific conditions. 2026-08-12 CVE-2026-68753 MEDIUM 5.3 Artifactory — An unauthenticated user may access restricted Artifactory content when a credentialed remote repository is con… 2026-08-12 CVE-2026-68754 MEDIUM 6.5 Artifactory — A repository publisher without delete permission may modify protected package content under specific condition… 2026-08-12 CVE-2026-68755 MEDIUM 4.3 Artifactory — A bundle writer may create misleading release promotion information under specific conditions. 2026-08-12 CVE-2026-68756 MEDIUM 6.6 Artifactory — A party with write access to stored session data may affect JFrog Artifactory under specific conditions. 2026-08-12 CVE-2026-68757 HIGH 7.5 Artifactory — A user with access to a valid SAML response may impersonate another user under specific conditions. 2026-08-12 CVE-2026-68758 MEDIUM 6.5 Artifactory — A low-privileged authenticated user may access restricted support information under specific conditions. 2026-08-12 CVE-2026-68759 HIGH 7.2 Artifactory — A holder of a valid integration credential may impersonate other users under specific conditions. 2026-08-12 CVE-2026-68760 MEDIUM 5.3 Artifactory — An unauthenticated user may bypass authentication under specific cache conditions. 2026-08-12 CVE-2026-69105 HIGH 8.1 Artifactory — An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potent… 2026-08-12 CVE-2026-69106 HIGH 8.8 Artifactory — A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consu… 2026-08-12 CVE-2026-69107 MEDIUM 5.9 Artifactory — An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions. 2026-08-12 CVE-2026-70547 MEDIUM 4.3 Artifactory — An authenticated user without repository read permission may access package metadata under specific conditions… 2026-08-12 CVE-2026-42016 HIGH 8.1 Artifactory — JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due t… 2026-07-27 CVE-2026-42017 HIGH 8.8 Artifactory — An event-handling weakness in JFrog Artifactory could expose privileged authorization material to a lower-priv… 2026-07-27 CVE-2026-65616 HIGH 8.8 Artifactory — Incorrect authorization validation in refresh token signature allows non-admin users to obtain a signed JFrog … 2026-07-27 CVE-2026-65617 HIGH 8.8 Artifactory — A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact c… 2026-07-27 CVE-2026-65618 MEDIUM 6.5 Artifactory — Improper URL validation when handling specific URLs, allows an attacker, under certain conditions, to make una… 2026-07-27 CVE-2026-65921 HIGH 8.8 Artifactory — A path validation weakness in archive extraction/write handling allows entries with traversal sequences to be … 2026-07-27 CVE-2026-65922 HIGH 7.1 Artifactory — An authorization weakness in JFrog Artifactory internal metadata handling could allow a user with limited repo… 2026-07-27 CVE-2026-65923 MEDIUM 6.8 Artifactory — A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user, under specific … 2026-07-27 CVE-2026-65924 MEDIUM 6.5 Artifactory — JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Server-Side Request… 2026-07-27 CVE-2026-65925 MEDIUM 6.5 Artifactory — A user with JFrog Artifactory Cargo remote repository read access could make Artifactory request unintended UR… 2026-07-27 CVE-2026-66014 HIGH 8.8 Artifactory — JFrog Artifactory contains an authentication handling weakness in internal request processing that, under spec… 2026-07-27 CVE-2026-66015 HIGH 7.2 Artifactory — An authenticated privilege-escalation vulnerability in JFrog Platform may be exploited under admin-provisioned… 2026-07-27 CVE-2026-66018 MEDIUM 6.5 Artifactory — Build readers can access another repository's environment properties. A caller with read access to an ordinary… 2026-07-27