Vulnerabilidades em jfrog

64 resultados
Análise Vexday

JFrog tem 13 vulnerabilidades catalogadas, todas publicadas nos últimos 90 dias, indicando exposição recente e concentrada. Nenhuma está sob exploração ativa (KEV) e não há críticas por CVSS, reduzindo o risco imediato. A fraqueza dominante é CWE-918 (SSRF), típica de plataformas que interagem com recursos remotos, exigindo validação rigorosa de URLs e redes internas.

CVE-2019-17444CRITICALJFrog Artifactory does not enforce default admin password changeEPSS 69.4%CVE-2026-42018HIGHAnonymous user token generation exposure in JFrog ArtifactoryEPSS 11.0%KEVCVE-2026-42016HIGHIncorrect authorization validation of user token in JFrog Artifactory allows Privilege EscalationEPSS 9.1%KEVCVE-2026-82329CRITICALPotential authentication bypass leading to administrative access in ArtifactoryEPSS 7.7%KEVCVE-2022-0573HIGHJFrog Artifactory before 7.36.1 and 6.23.41, is vulnerable to Insecure Deserialization of untrusted data which can lead to DoS, Privilege EsEPSS 2.0%CVE-2021-3860HIGHJFrog Artifactory before 7.25.4 (Enterprise+ deployments only), is vulnerable to Blind SQL Injection by a low privileged authenticated user EPSS 1.0%CVE-2023-42661HIGHJFrog Artifactory Improper input validation leads to arbitrary file writeEPSS 0.9%CVE-2021-46687MEDIUMJFrog Artifactory prior to version 7.31.10 and 6.23.38 is vulnerable to Sensitive Data Exposure through the Project Administrator REST API. EPSS 0.8%CVE-2024-4142CRITICALJFrog Artifactory Improper input validation within token creation flowEPSS 0.7%CVE-2026-65617HIGHPotential remote code execution on an Artifactory package service container.EPSS 0.7%CVE-2026-66015HIGHJFrog Platform contains an authorization flaw that may allow authenticated privilege escalation.EPSS 0.6%CVE-2021-46270LOWJFrog Artifactory before 7.31.10, is vulnerable to Broken Access Control where a project admin user is able to list all available repositoryEPSS 0.6%CVE-2026-65921HIGHPotential path traversal leading to unauthorized file writesEPSS 0.6%CVE-2026-66014HIGHPotential authentication bypass leading to privilege escalation in ArtifactoryEPSS 0.6%CVE-2021-45074MEDIUMJFrog Artifactory before 7.29.3 and 6.23.38, is vulnerable to Broken Access Control, a low-privileged user is able to delete other known useEPSS 0.6%CVE-2022-0668MEDIUMJFrog Artifactory prior to 7.37.13 is vulnerable to Authentication Bypass, which can lead to Privilege Escalation when a specially crafted rEPSS 0.6%CVE-2024-6915CRITICALJFrog Artifactory Cache PoisoningEPSS 0.6%CVE-2026-66384MEDIUMAuthenticated users may write data outside the intended Docker cache pathEPSS 0.6%KEVCVE-2021-41834MEDIUMJFrog Artifactory prior to version 7.28.0 and 6.23.38, is vulnerable to Broken Access Control, the copy functionality can be used by a low-pEPSS 0.6%CVE-2021-45721MEDIUMJFrog Artifactory prior to version 7.29.8 and 6.23.38 is vulnerable to Reflected Cross-Site Scripting (XSS) through one of the XHR parameterEPSS 0.6%