JFrog Artifactory 在处理 Composer 仓库时存在授权弱点,在特定条件下,可能允许经过身份验证的用户读取其无权访问的仓库中的软件包元数据。该问题影响数据的机密性,并已在已修复的 Artifactory 版本中得以解决。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| jfrog | artifactory | 7.161.0< 7.161.19 |
affected |
7.146.0< 7.146.29 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| jfrog | artifactory | 7.161.0 ~ 7.161.19 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-70551 | 8.5 HIGH | Server-Side Request Forgery Via VCS remote download in JFrog Artifactory |
| CVE-2026-69104 | 7.6 HIGH | Potential unauthorized repository migration in JFrog Artifactory |
| CVE-2026-70548 | 3.5 LOW | SSRF In CocoaPods Via JFrog Artifactory External Dependency |
No comments yet