Vulnerabilidades em JFrog
34 resultadosAnálise Vexday
JFrog apresenta 20 CVEs catalogadas, com 3 classificadas como críticas, mas nenhuma sob ataque ativo conhecido (KEV = 0) e nenhuma publicação nos últimos 90 dias, indicando risco estável. A fraqueza dominante é validação inadequada de entrada (CWE-20), típica de falhas de controle de dados que requerem monitoramento contínuo. O panorama sugere vulnerabilidades legadas sem exploração em massa, reduzindo urgência de remediação imediata, embora as críticas demandem avaliação de impacto.
CVE-2026-66015HIGHJFrog Platform contains an authorization flaw that may allow authenticated privilege escalation.EPSS 0.3%CVE-2026-66014HIGHPotential authentication bypass leading to privilege escalation in ArtifactoryEPSS 0.3%CVE-2026-65617HIGHPotential remote code execution on an Artifactory package service container.EPSS 0.3%CVE-2026-42017HIGHPrivilege escalation via JFrog Worker event token exposureEPSS 0.3%CVE-2024-2248MEDIUMJFrog Artifactory Header InjectionEPSS 0.3%CVE-2025-14830MEDIUMJFrog Artifactory Cross-Site ScriptingEPSS 0.2%CVE-2026-66018MEDIUMJFrog Artifactory build environment properties exposureEPSS 0.2%CVE-2026-42016HIGHIncorrect authorization validation of user token in JFrog Artifactory allows Privilege EscalationEPSS 0.2%CVE-2026-65924MEDIUMServer-Side Request Forgery (SSRF) via Terraform Remote repositoryEPSS 0.2%CVE-2026-65618MEDIUMImproper URL validation when handling specific URLs Pub, Terraform and Docker packages might lead to SSRF vulnerabilityEPSS 0.2%CVE-2026-65925MEDIUMServer-Side Request Forgery (SSRF) via JFrog Artifactory Cargo remote repositoryEPSS 0.2%CVE-2026-65923MEDIUMPotential server-side request forgery in Artifactory Ansible repository handlingEPSS 0.2%CVE-2026-65616HIGHPotential privilege escalation to JFrog administrator privilegesEPSS 0.2%CVE-2026-65922HIGHPotential unauthorized modification of Artifactory internal metadataEPSS 0.2%