Vulnerabilidades em jfrog
64 resultadosAnálise Vexday
JFrog tem 13 vulnerabilidades catalogadas, todas publicadas nos últimos 90 dias, indicando exposição recente e concentrada. Nenhuma está sob exploração ativa (KEV) e não há críticas por CVSS, reduzindo o risco imediato. A fraqueza dominante é CWE-918 (SSRF), típica de plataformas que interagem com recursos remotos, exigindo validação rigorosa de URLs e redes internas.
CVE-2024-2248MEDIUMJFrog Artifactory Header InjectionEPSS 0.3%CVE-2026-66377MEDIUMAnonymous users may access restricted Artifactory repository informationEPSS 0.3%CVE-2026-66382MEDIUMAuthenticated users may write files outside the intended Artifactory work directoryEPSS 0.3%CVE-2026-68758MEDIUMAuthenticated users may access restricted Artifactory support informationEPSS 0.3%CVE-2026-65922HIGHPotential unauthorized modification of Artifactory internal metadataEPSS 0.3%CVE-2026-68753MEDIUMAnonymous users may access restricted Artifactory content under specific configurationsEPSS 0.2%CVE-2026-68759HIGHIntegration credential holders may impersonate users in JFrog AccessEPSS 0.2%CVE-2026-65616HIGHPotential privilege escalation to JFrog administrator privilegesEPSS 0.2%CVE-2026-68754MEDIUMPublishers without delete permission can overwrite docker layer informationEPSS 0.2%CVE-2026-66379MEDIUMAuthenticated users may view private Puppet module metadataEPSS 0.2%CVE-2026-66378MEDIUMAuthenticated users may access private NuGet metadataEPSS 0.2%CVE-2026-66380MEDIUMAuthenticated users may access private OCI referrer metadataEPSS 0.2%CVE-2026-70550MEDIUMPotential unauthorized access to private Composer repository metadata in JFrog ArtifactoryEPSS 0.2%CVE-2026-65618MEDIUMImproper URL validation when handling specific URLs Pub, Terraform and Docker packages might lead to SSRF vulnerabilityEPSS 0.2%CVE-2026-70547MEDIUMPotential unauthorized metadata exposure in JFrog ArtifactoryEPSS 0.2%CVE-2026-68757HIGHPotential improper SAML signature verification in JFrog ArtifactoryEPSS 0.2%CVE-2026-68755MEDIUMBundle writers may alter trusted release information in JFrog ArtifactoryEPSS 0.2%CVE-2026-65926LOWPrivate Release Bundle versions may be disclosed under specific configurationsEPSS 0.2%CVE-2026-70548LOWSSRF In CocoaPods Via JFrog Artifactory External DependencyEPSS 0.2%CVE-2026-70551HIGHServer-Side Request Forgery Via VCS remote download in JFrog ArtifactoryEPSS 0.2%