JFrog artifactory是美国JFrog公司的一个二进制制品仓库管理平台。 JFrog artifactory 7.146.35之前版本和7.161.0至7.161.16之前版本存在路径遍历漏洞,该漏洞源于路径遍历,经过身份验证的用户在特定远程仓库条件下可能将数据写入预期Docker缓存路径之外。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| jfrog | artifactory | < 7.146.35 |
affected |
7.161.0< 7.161.16 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| jfrog | artifactory | 0 ~ 7.146.35 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-69106 | 8.8 HIGH | Potential cache poisoning in JFrog Artifactory |
| CVE-2026-69105 | 8.1 HIGH | Potential package cache integrity issue in JFrog Artifactory |
| CVE-2026-66375 | 8.1 HIGH | Low-privilege users may remove protected Artifactory metadata |
| CVE-2026-42018 | 7.5 HIGH | Anonymous user token generation exposure in JFrog Artifactory |
| CVE-2026-68757 | 7.5 HIGH | Potential improper SAML signature verification in JFrog Artifactory |
| CVE-2026-68759 | 7.2 HIGH | Integration credential holders may impersonate users in JFrog Access |
| CVE-2026-68752 | 7.2 HIGH | Project Resource Managers may escalate privileges in JFrog Artifactory |
| CVE-2026-66016 | 6.7 MEDIUM | Rendered Artifactory Helm manifests may contain generated TLS private keys |
| CVE-2026-68756 | 6.6 MEDIUM | Potential insecure deserialization in JFrog Artifactory |
| CVE-2026-68754 | 6.5 MEDIUM | Publishers without delete permission can overwrite docker layer information |
| CVE-2026-68758 | 6.5 MEDIUM | Authenticated users may access restricted Artifactory support information |
| CVE-2026-69107 | 5.9 MEDIUM | Potential unauthorized artifact access in JFrog Artifactory |
| CVE-2026-68760 | 5.3 MEDIUM | Potential remember-me authentication bypass in JFrog Artifactory |
| CVE-2026-68753 | 5.3 MEDIUM | Anonymous users may access restricted Artifactory content under specific configurations |
| CVE-2026-66377 | 5.3 MEDIUM | Anonymous users may access restricted Artifactory repository information |
| CVE-2026-66381 | 5.3 MEDIUM | Repository readers may access content outside configured upstream paths |
| CVE-2026-68755 | 4.3 MEDIUM | Bundle writers may alter trusted release information in JFrog Artifactory |
| CVE-2026-66382 | 4.3 MEDIUM | Authenticated users may write files outside the intended Artifactory work directory |
| CVE-2026-66380 | 4.3 MEDIUM | Authenticated users may access private OCI referrer metadata |
| CVE-2026-66378 | 4.3 MEDIUM | Authenticated users may access private NuGet metadata |
Showing top 20 of 25 CVEs. View all on vendor page → →
No comments yet