Jfrog

Artifactory

79 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Warnung Medienbericht
  • EPSS 0.38%
  • Veröffentlicht 28.08.2026 18:27:43
  • Zuletzt bearbeitet 03.09.2026 13:06:15

JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.

  • EPSS 0.21%
  • Veröffentlicht 25.08.2026 15:22:53
  • Zuletzt bearbeitet 28.08.2026 21:29:30

An authorization weakness in JFrog Artifactory Composer repository handling may allow an authenticated user, under specific conditions, to read package metadata from repositories they are not authorized to read. The issue affects confidentiality and ...

  • EPSS 0.18%
  • Veröffentlicht 25.08.2026 15:17:16
  • Zuletzt bearbeitet 28.08.2026 21:29:30

Under specific circumstances, low-level user can run request to remote CocoaPods repos via JFrog Artifactory External Dependency.

  • EPSS 0.18%
  • Veröffentlicht 25.08.2026 15:16:38
  • Zuletzt bearbeitet 28.08.2026 21:29:30

A user who can read an existing remote VCS repository can replace its configured origin or supply an absolute VCS data URL.

  • EPSS 0.18%
  • Veröffentlicht 25.08.2026 15:16:37
  • Zuletzt bearbeitet 28.08.2026 21:29:30

An authenticated user may initiate repository migration operations without required repository permissions, potentially causing information disclosure, unauthorized state changes, and service disruption. Fixed versions address the issue.

Medienbericht
  • EPSS 0.35%
  • Veröffentlicht 12.08.2026 17:48:29
  • Zuletzt bearbeitet 11.09.2026 15:36:31

A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers to retrieve untrusted content.

Warnung Medienbericht
  • EPSS 0.3%
  • Veröffentlicht 12.08.2026 17:43:21
  • Zuletzt bearbeitet 01.10.2026 19:17:20

JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.

  • EPSS 0.28%
  • Veröffentlicht 12.08.2026 15:51:47
  • Zuletzt bearbeitet 11.09.2026 18:45:52

An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions.

  • EPSS 0.13%
  • Veröffentlicht 12.08.2026 15:19:40
  • Zuletzt bearbeitet 11.09.2026 18:49:47

An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affecting artifact integrity and availability.

  • EPSS 0.2%
  • Veröffentlicht 12.08.2026 15:18:29
  • Zuletzt bearbeitet 11.09.2026 18:43:59

An authenticated user without repository read permission may access package metadata under specific conditions.