Vulnerabilities in JFrog
64 resultsVexday analysis
JFrog apresenta 20 CVEs catalogadas, com 3 classificadas como críticas, mas nenhuma sob ataque ativo conhecido (KEV = 0) e nenhuma publicação nos últimos 90 dias, indicando risco estável. A fraqueza dominante é validação inadequada de entrada (CWE-20), típica de falhas de controle de dados que requerem monitoramento contínuo. O panorama sugere vulnerabilidades legadas sem exploração em massa, reduzindo urgência de remediação imediata, embora as críticas demandem avaliação de impacto.
CVE-2019-17444CRITICALJFrog Artifactory does not enforce default admin password changeEPSS 69.4%CVE-2026-82329CRITICALPotential authentication bypass leading to administrative access in ArtifactoryEPSS 14.1%KEVCVE-2026-42018HIGHAnonymous user token generation exposure in JFrog ArtifactoryEPSS 9.8%KEVCVE-2026-42016HIGHIncorrect authorization validation of user token in JFrog Artifactory allows Privilege EscalationEPSS 8.6%KEVCVE-2022-0573HIGHJFrog Artifactory before 7.36.1 and 6.23.41, is vulnerable to Insecure Deserialization of untrusted data which can lead to DoS, Privilege EsEPSS 2.0%CVE-2021-3860HIGHJFrog Artifactory before 7.25.4 (Enterprise+ deployments only), is vulnerable to Blind SQL Injection by a low privileged authenticated user EPSS 1.0%CVE-2023-42661HIGHJFrog Artifactory Improper input validation leads to arbitrary file writeEPSS 0.9%CVE-2021-46687MEDIUMJFrog Artifactory prior to version 7.31.10 and 6.23.38 is vulnerable to Sensitive Data Exposure through the Project Administrator REST API. EPSS 0.8%CVE-2024-4142CRITICALJFrog Artifactory Improper input validation within token creation flowEPSS 0.7%CVE-2026-66384MEDIUMAuthenticated users may write data outside the intended Docker cache pathEPSS 0.7%KEVCVE-2026-65617HIGHPotential remote code execution on an Artifactory package service container.EPSS 0.6%CVE-2021-46270LOWJFrog Artifactory before 7.31.10, is vulnerable to Broken Access Control where a project admin user is able to list all available repositoryEPSS 0.6%CVE-2026-66014HIGHPotential authentication bypass leading to privilege escalation in ArtifactoryEPSS 0.6%CVE-2021-45074MEDIUMJFrog Artifactory before 7.29.3 and 6.23.38, is vulnerable to Broken Access Control, a low-privileged user is able to delete other known useEPSS 0.6%CVE-2022-0668MEDIUMJFrog Artifactory prior to 7.37.13 is vulnerable to Authentication Bypass, which can lead to Privilege Escalation when a specially crafted rEPSS 0.6%CVE-2024-6915CRITICALJFrog Artifactory Cache PoisoningEPSS 0.6%CVE-2026-65921HIGHPotential path traversal leading to unauthorized file writesEPSS 0.6%CVE-2021-41834MEDIUMJFrog Artifactory prior to version 7.28.0 and 6.23.38, is vulnerable to Broken Access Control, the copy functionality can be used by a low-pEPSS 0.6%CVE-2026-66015HIGHJFrog Platform contains an authorization flaw that may allow authenticated privilege escalation.EPSS 0.6%CVE-2021-45721MEDIUMJFrog Artifactory prior to version 7.29.8 and 6.23.38 is vulnerable to Reflected Cross-Site Scripting (XSS) through one of the XHR parameterEPSS 0.6%