Jfrog

Artifactory

74 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.19%
  • Veröffentlicht 27.07.2026 19:34:17
  • Zuletzt bearbeitet 30.07.2026 14:49:28

Incorrect authorization validation in refresh token signature allows non-admin users to obtain a signed JFrog administrator token.

Medienbericht
  • EPSS 0.39%
  • Veröffentlicht 27.07.2026 19:33:27
  • Zuletzt bearbeitet 30.07.2026 14:46:12

An authenticated privilege-escalation vulnerability in JFrog Platform may be exploited under admin-provisioned account conditions. Successful exploitation may grant temporary platform administrator access.

Medienbericht
  • EPSS 0.21%
  • Veröffentlicht 27.07.2026 19:32:29
  • Zuletzt bearbeitet 30.07.2026 14:51:10

Improper URL validation when handling specific URLs, allows an attacker, under certain conditions, to make unauthorized requests from JFrog Artifactory, potentially exposing internal services and cached response data.

Medienbericht
  • EPSS 0.23%
  • Veröffentlicht 27.07.2026 19:31:34
  • Zuletzt bearbeitet 30.07.2026 14:46:20

Build readers can access another repository's environment properties. A caller with read access to an ordinary repository can select a readable repository parameter while retrieving environment properties for a protected build, exposing build environ...

Medienbericht
  • EPSS 0.32%
  • Veröffentlicht 27.07.2026 19:29:47
  • Zuletzt bearbeitet 30.07.2026 14:45:38

JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.

Medienbericht
  • EPSS 0.37%
  • Veröffentlicht 27.07.2026 19:27:31
  • Zuletzt bearbeitet 30.07.2026 14:51:26

A path validation weakness in archive extraction/write handling allows entries with traversal sequences to be written outside the intended build artifacts location.

  • EPSS 0.29%
  • Veröffentlicht 27.07.2026 19:26:23
  • Zuletzt bearbeitet 30.07.2026 14:41:34

An event-handling weakness in JFrog Artifactory could expose privileged authorization material to a lower-privileged user under specific conditions.

  • EPSS 0.23%
  • Veröffentlicht 27.07.2026 19:20:56
  • Zuletzt bearbeitet 30.07.2026 14:42:56

JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.

  • EPSS 0.24%
  • Veröffentlicht 04.01.2026 09:17:34
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in JFrog Artifactory (Workers) allows Cross-Site Scripting (XSS).This issue affects Artifactory (Workers): from >=7.94.0 through <7.117.10.

  • EPSS 0.6%
  • Veröffentlicht 05.08.2024 20:15:36
  • Zuletzt bearbeitet 15.04.2026 00:35:42

JFrog Artifactory versions below 7.90.6, 7.84.20, 7.77.14, 7.71.23, 7.68.22, 7.63.22, 7.59.23, 7.55.18 are vulnerable to Improper Input Validation that could potentially lead to cache poisoning.