经过身份验证的用户可能在缺乏必要仓库权限的情况下发起仓库迁移操作,这可能导致信息泄露、未经授权的狀態变更和服务中断。已修复版本解决了此问题。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| jfrog | artifactory | 7.161.0< 7.161.19 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| jfrog | artifactory | 7.161.0 ~ 7.161.19 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-70551 | 8.5 HIGH | Server-Side Request Forgery Via VCS remote download in JFrog Artifactory |
| CVE-2026-70550 | 6.5 MEDIUM | Potential unauthorized access to private Composer repository metadata in JFrog Artifactory |
| CVE-2026-70548 | 3.5 LOW | SSRF In CocoaPods Via JFrog Artifactory External Dependency |
No comments yet