Search Results (75 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-70547 1 Jfrog 1 Artifactory 2026-08-13 4.3 Medium
An authenticated user without repository read permission may access package metadata under specific conditions.
CVE-2026-69105 1 Jfrog 1 Artifactory 2026-08-13 8.1 High
An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affecting artifact integrity and availability.
CVE-2026-66378 1 Jfrog 1 Artifactory 2026-08-13 4.3 Medium
An authenticated user without repository read permission may access private NuGet metadata under specific conditions.
CVE-2026-66377 1 Jfrog 1 Artifactory 2026-08-13 5.3 Medium
An unauthenticated user may access restricted repository information under specific conditions.
CVE-2026-42018 1 Jfrog 1 Artifactory 2026-08-13 7.5 High
JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
CVE-2026-69106 1 Jfrog 1 Artifactory 2026-08-13 8.8 High
A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers to retrieve untrusted content.
CVE-2026-68752 1 Jfrog 1 Artifactory 2026-08-13 7.2 High
A Project Resource Manager may gain broader administrative privileges under specific conditions.
CVE-2026-68758 1 Jfrog 1 Artifactory 2026-08-13 6.5 Medium
A low-privileged authenticated user may access restricted support information under specific conditions.
CVE-2026-68760 1 Jfrog 1 Artifactory 2026-08-12 5.3 Medium
An unauthenticated user may bypass authentication under specific cache conditions.
CVE-2026-68753 1 Jfrog 1 Artifactory 2026-08-12 5.3 Medium
An unauthenticated user may access restricted Artifactory content when a credentialed remote repository is configured in a specific way.
CVE-2026-66016 1 Jfrog 1 Artifactory 2026-08-12 6.7 Medium
Under specific self-hosted Helm configurations, generated TLS private keys may be retained in rendered manifests accessible to highly privileged local users.
CVE-2026-68757 1 Jfrog 1 Artifactory 2026-08-12 7.5 High
A user with access to a valid SAML response may impersonate another user under specific conditions.
CVE-2026-66376 1 Jfrog 1 Artifactory 2026-08-12 4.2 Medium
Credentials for a deleted user may remain valid for a short period under specific conditions.
CVE-2026-66380 1 Jfrog 1 Artifactory 2026-08-12 4.3 Medium
An authenticated user without repository read permission may access private OCI referrer metadata under specific conditions.
CVE-2026-68755 1 Jfrog 1 Artifactory 2026-08-12 4.3 Medium
A bundle writer may create misleading release promotion information under specific conditions.
CVE-2026-66382 1 Jfrog 1 Artifactory 2026-08-12 4.3 Medium
An authenticated user may write files outside the intended Artifactory work directory under specific conditions.
CVE-2026-69107 1 Jfrog 1 Artifactory 2026-08-12 5.9 Medium
An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions.
CVE-2026-68759 1 Jfrog 1 Artifactory 2026-08-12 7.2 High
A holder of a valid integration credential may impersonate other users under specific conditions.
CVE-2026-66384 1 Jfrog 1 Artifactory 2026-08-12 5.3 Medium
An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.
CVE-2026-66381 1 Jfrog 1 Artifactory 2026-08-12 5.3 Medium
A repository reader with cache-deploy permission may access content outside a configured upstream path under specific conditions.