Vulnerabilities in Jfrog
64 resultsVexday analysis
JFrog apresenta footprint mínimo de risco com apenas 1 CVE crítica registrada na base, sem incidentes de exploração ativa conhecida (KEV). A vulnerabilidade documentada relaciona-se a gestão inadequada de credenciais (CWE-521), risco tradicional em plataformas de artifact management, porém sem atividade recente de descoberta ou atualização.
CVE-2026-65618MEDIUMImproper URL validation when handling specific URLs Pub, Terraform and Docker packages might lead to SSRF vulnerabilityEPSS 0.4%CVE-2026-68758MEDIUMAuthenticated users may access restricted Artifactory support informationEPSS 0.4%CVE-2026-65925MEDIUMServer-Side Request Forgery (SSRF) via JFrog Artifactory Cargo remote repositoryEPSS 0.4%CVE-2026-66382MEDIUMAuthenticated users may write files outside the intended Artifactory work directoryEPSS 0.4%CVE-2026-68759HIGHIntegration credential holders may impersonate users in JFrog AccessEPSS 0.3%CVE-2026-68754MEDIUMPublishers without delete permission can overwrite docker layer informationEPSS 0.3%CVE-2026-69104HIGHPotential unauthorized repository migration in JFrog ArtifactoryEPSS 0.3%CVE-2026-68753MEDIUMAnonymous users may access restricted Artifactory content under specific configurationsEPSS 0.3%CVE-2026-65923MEDIUMPotential server-side request forgery in Artifactory Ansible repository handlingEPSS 0.3%CVE-2026-65922HIGHPotential unauthorized modification of Artifactory internal metadataEPSS 0.3%CVE-2026-66380MEDIUMAuthenticated users may access private OCI referrer metadataEPSS 0.3%CVE-2026-66379MEDIUMAuthenticated users may view private Puppet module metadataEPSS 0.3%CVE-2026-66378MEDIUMAuthenticated users may access private NuGet metadataEPSS 0.3%CVE-2026-70551HIGHServer-Side Request Forgery Via VCS remote download in JFrog ArtifactoryEPSS 0.3%CVE-2026-70548LOWSSRF In CocoaPods Via JFrog Artifactory External DependencyEPSS 0.3%CVE-2026-70547MEDIUMPotential unauthorized metadata exposure in JFrog ArtifactoryEPSS 0.3%CVE-2025-14830MEDIUMJFrog Artifactory Cross-Site ScriptingEPSS 0.3%CVE-2024-2248MEDIUMJFrog Artifactory Header InjectionEPSS 0.3%CVE-2026-68757HIGHPotential improper SAML signature verification in JFrog ArtifactoryEPSS 0.3%CVE-2026-68755MEDIUMBundle writers may alter trusted release information in JFrog ArtifactoryEPSS 0.3%