Search
Search Results (7 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-65617 | 1 Jfrog | 1 Artifactory | 2026-07-28 | 8.8 High |
| A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact confidentiality, integrity, and availability under specific repository conditions. | ||||
| CVE-2026-66014 | 1 Jfrog | 1 Artifactory | 2026-07-28 | 8.8 High |
| JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level. | ||||
| CVE-2026-65921 | 1 Jfrog | 1 Artifactory | 2026-07-28 | 8.8 High |
| A path validation weakness in archive extraction/write handling allows entries with traversal sequences to be written outside the intended build artifacts location. | ||||
| CVE-2026-66018 | 1 Jfrog | 1 Artifactory | 2026-07-28 | 6.5 Medium |
| Build readers can access another repository's environment properties. A caller with read access to an ordinary repository can select a readable repository parameter while retrieving environment properties for a protected build, exposing build environment secrets (confidentiality impact; no integrity or availability impact demonstrated). | ||||
| CVE-2026-65923 | 1 Jfrog | 1 Artifactory | 2026-07-28 | 6.8 Medium |
| A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user, under specific repository access conditions, to cause unintended server-side requests. The issue primarily affects confidentiality and integrity and has been addressed in fixed Artifactory versions. | ||||
| CVE-2026-42016 | 1 Jfrog | 1 Artifactory | 2026-07-28 | 8.1 High |
| JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope. | ||||
| CVE-2026-42017 | 1 Jfrog | 1 Artifactory | 2026-07-28 | 8.8 High |
| An event-handling weakness in JFrog Artifactory could expose privileged authorization material to a lower-privileged user under specific conditions. | ||||
Page 1 of 1.