Search Results (79 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-68756 1 Jfrog 1 Artifactory 2026-09-02 6.6 Medium
A party with write access to stored session data may affect JFrog Artifactory under specific conditions.
CVE-2026-68757 1 Jfrog 1 Artifactory 2026-09-02 7.5 High
A user with access to a valid SAML response may impersonate another user under specific conditions.
CVE-2026-68760 1 Jfrog 1 Artifactory 2026-09-02 5.3 Medium
An unauthenticated user may bypass authentication under specific cache conditions.
CVE-2026-68758 1 Jfrog 1 Artifactory 2026-09-02 6.5 Medium
A low-privileged authenticated user may access restricted support information under specific conditions.
CVE-2026-68759 1 Jfrog 1 Artifactory 2026-09-02 7.2 High
A holder of a valid integration credential may impersonate other users under specific conditions.
CVE-2026-66384 1 Jfrog 1 Artifactory 2026-08-27 5.3 Medium
An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.
CVE-2026-70551 1 Jfrog 1 Artifactory 2026-08-26 8.5 High
A user who can read an existing remote VCS repository can replace its configured origin or supply an absolute VCS data URL.
CVE-2026-70550 1 Jfrog 1 Artifactory 2026-08-26 6.5 Medium
An authorization weakness in JFrog Artifactory Composer repository handling may allow an authenticated user, under specific conditions, to read package metadata from repositories they are not authorized to read. The issue affects confidentiality and has been addressed in fixed Artifactory versions.
CVE-2026-70548 1 Jfrog 1 Artifactory 2026-08-26 3.5 Low
Under specific circumstances, low-level user can run request to remote CocoaPods repos via JFrog Artifactory External Dependency.
CVE-2026-69104 1 Jfrog 1 Artifactory 2026-08-25 7.6 High
An authenticated user may initiate repository migration operations without required repository permissions, potentially causing information disclosure, unauthorized state changes, and service disruption. Fixed versions address the issue.
CVE-2026-65926 1 Jfrog 1 Artifactory 2026-08-12 3.1 Low
An anonymous caller when anonymous access is enabled, or a low-privilege authenticated user, may learn private Release Bundle names and versions when the bundle name is known.
CVE-2026-65618 1 Jfrog 1 Artifactory 2026-07-28 6.5 Medium
Improper URL validation when handling specific URLs, allows an attacker, under certain conditions, to make unauthorized requests from JFrog Artifactory, potentially exposing internal services and cached response data.
CVE-2026-65616 1 Jfrog 1 Artifactory 2026-07-28 8.8 High
Incorrect authorization validation in refresh token signature allows non-admin users to obtain a signed JFrog administrator token.
CVE-2026-65925 1 Jfrog 1 Artifactory 2026-07-28 6.5 Medium
A user with JFrog Artifactory Cargo remote repository read access could make Artifactory request unintended URLs and return the response.
CVE-2026-65617 1 Jfrog 1 Artifactory 2026-07-28 8.8 High
A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact confidentiality, integrity, and availability under specific repository conditions.
CVE-2026-65922 1 Jfrog 1 Artifactory 2026-07-28 7.1 High
An authorization weakness in JFrog Artifactory internal metadata handling could allow a user with limited repository access to write to restricted internal metadata areas under specific conditions. Successful abuse is limited to integrity and availability impact at a low level; confidentiality is not affected.
CVE-2026-66014 1 Jfrog 1 Artifactory 2026-07-28 8.8 High
JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.
CVE-2026-65924 1 Jfrog 1 Artifactory 2026-07-28 6.5 Medium
JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Server-Side Request Forgery (SSRF). An authenticated user - or, if anonymous access is enabled on the repository, an unauthenticated user - could cause Artifactory to issue outbound HTTP requests to arbitrary destinations and receive the response content.
CVE-2026-65921 1 Jfrog 1 Artifactory 2026-07-28 8.8 High
A path validation weakness in archive extraction/write handling allows entries with traversal sequences to be written outside the intended build artifacts location.
CVE-2026-66018 1 Jfrog 1 Artifactory 2026-07-28 6.5 Medium
Build readers can access another repository's environment properties. A caller with read access to an ordinary repository can select a readable repository parameter while retrieving environment properties for a protected build, exposing build environment secrets (confidentiality impact; no integrity or availability impact demonstrated).