Jfrog

Artifactory

74 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.08%
  • Veröffentlicht 12.08.2026 15:16:39
  • Zuletzt bearbeitet 12.08.2026 19:17:36

Under specific self-hosted Helm configurations, generated TLS private keys may be retained in rendered manifests accessible to highly privileged local users.

  • EPSS 0.23%
  • Veröffentlicht 12.08.2026 15:15:50
  • Zuletzt bearbeitet 12.08.2026 19:17:54

A holder of a valid integration credential may impersonate other users under specific conditions.

  • EPSS 0.19%
  • Veröffentlicht 12.08.2026 15:14:42
  • Zuletzt bearbeitet 12.08.2026 19:17:35

An anonymous caller when anonymous access is enabled, or a low-privilege authenticated user, may learn private Release Bundle names and versions when the bundle name is known.

  • EPSS 0.26%
  • Veröffentlicht 12.08.2026 15:14:04
  • Zuletzt bearbeitet 12.08.2026 19:17:37

An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.

  • EPSS 0.26%
  • Veröffentlicht 12.08.2026 15:12:56
  • Zuletzt bearbeitet 12.08.2026 19:17:53

A low-privileged authenticated user may access restricted support information under specific conditions.

Medienbericht
  • EPSS 0.18%
  • Veröffentlicht 27.07.2026 19:44:44
  • Zuletzt bearbeitet 30.07.2026 14:43:18

An authorization weakness in JFrog Artifactory internal metadata handling could allow a user with limited repository access to write to restricted internal metadata areas under specific conditions. Successful abuse is limited to integrity and availab...

Medienbericht
  • EPSS 0.19%
  • Veröffentlicht 27.07.2026 19:43:46
  • Zuletzt bearbeitet 30.07.2026 14:44:14

A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user, under specific repository access conditions, to cause unintended server-side requests. The issue primarily affects confidentiality and integrity and has be...

Medienbericht
  • EPSS 0.31%
  • Veröffentlicht 27.07.2026 19:37:27
  • Zuletzt bearbeitet 30.07.2026 14:49:42

A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact confidentiality, integrity, and availability under specific repository conditions.

Medienbericht
  • EPSS 0.22%
  • Veröffentlicht 27.07.2026 19:36:35
  • Zuletzt bearbeitet 30.07.2026 14:44:38

JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Server-Side Request Forgery (SSRF). An authenticated user - or, if anonymous access is enabled on the repository, an unauthenticated user - could cause Artifac...

Medienbericht
  • EPSS 0.21%
  • Veröffentlicht 27.07.2026 19:35:17
  • Zuletzt bearbeitet 30.07.2026 14:45:18

A user with JFrog Artifactory Cargo remote repository read access could make Artifactory request unintended URLs and return the response.