← Back

Artifactory

artifactory

Vendor: Jfrog • 64 CVEs

CVEs (64)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jfrog
1Artifactory
Sep 3, 2026
Aug 28, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.
1Jfrog
1Artifactory
Sep 2, 2026
Aug 12, 2026
N/A· v4
7.2 HIGH· v3
N/A· v2
A holder of a valid integration credential may impersonate other users under specific conditions.
1Jfrog
1Artifactory
Sep 2, 2026
Aug 12, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A low-privileged authenticated user may access restricted support information under specific conditions.
1Jfrog
1Artifactory
Aug 28, 2026
Aug 12, 2026
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.
1Jfrog
1Artifactory
Sep 2, 2026
Aug 12, 2026
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An unauthenticated user may bypass authentication under specific cache conditions.
1Jfrog
1Artifactory
Sep 2, 2026
Aug 12, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
A user with access to a valid SAML response may impersonate another user under specific conditions.
1Jfrog
1Artifactory
Sep 2, 2026
Aug 12, 2026
N/A· v4
6.6 MEDIUM· v3
N/A· v2
A party with write access to stored session data may affect JFrog Artifactory under specific conditions.
1Jfrog
1Artifactory
Sep 2, 2026
Aug 12, 2026
N/A· v4
4.3 MEDIUM· v3
N/A· v2
A bundle writer may create misleading release promotion information under specific conditions.
1Jfrog
1Artifactory
Sep 2, 2026
Aug 12, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A repository publisher without delete permission may modify protected package content under specific conditions.
1Jfrog
1Artifactory
Sep 2, 2026
Aug 12, 2026
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An unauthenticated user may access restricted Artifactory content when a credentialed remote repository is configured in a specific way.
1Jfrog
1Artifactory
Sep 2, 2026
Aug 12, 2026
N/A· v4
7.2 HIGH· v3
N/A· v2
A Project Resource Manager may gain broader administrative privileges under specific conditions.
1Jfrog
1Artifactory
Sep 2, 2026
Aug 12, 2026
N/A· v4
4.3 MEDIUM· v3
N/A· v2
An authenticated user may write files outside the intended Artifactory work directory under specific conditions.
1Jfrog
1Artifactory
Sep 2, 2026
Aug 12, 2026
N/A· v4
5.3 MEDIUM· v3
N/A· v2
A repository reader with cache-deploy permission may access content outside a configured upstream path under specific conditions.
1Jfrog
1Artifactory
Sep 2, 2026
Aug 12, 2026
N/A· v4
4.3 MEDIUM· v3
N/A· v2
An authenticated user without repository read permission may access private OCI referrer metadata under specific conditions.
1Jfrog
1Artifactory
Sep 2, 2026
Aug 12, 2026
N/A· v4
4.3 MEDIUM· v3
N/A· v2
An authenticated user may view private Puppet module metadata without repository read access.
1Jfrog
1Artifactory
Sep 2, 2026
Aug 12, 2026
N/A· v4
4.3 MEDIUM· v3
N/A· v2
An authenticated user without repository read permission may access private NuGet metadata under specific conditions.
1Jfrog
1Artifactory
Sep 2, 2026
Aug 12, 2026
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An unauthenticated user may access restricted repository information under specific conditions.
1Jfrog
1Artifactory
Sep 2, 2026
Aug 12, 2026
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Credentials for a deleted user may remain valid for a short period under specific conditions.
1Jfrog
1Artifactory
Sep 2, 2026
Aug 12, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
A low-privilege authenticated user may permanently remove protected internal metadata across repositories under specific conditions.
1Jfrog
1Artifactory
Jul 30, 2026
Jul 27, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Build readers can access another repository's environment properties. A caller with read access to an ordinary repository can select a readable repository parameter while retrieving environment properties for a protected...Show more
Build readers can access another repository's environment properties. A caller with read access to an ordinary repository can select a readable repository parameter while retrieving environment properties for a protected build, exposing build environment secrets (confidentiality impact; no integrity or availability impact demonstrated).Show less