Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

artifactory — Vulnerabilities & Security Advisories 24

All 24 CVE vulnerabilities found in artifactory, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known vulnerabilities and weaknesses associated with the Artifactory product, provided by JFrog. It focuses on standard weakness categories such as cross-site scripting, privilege escalation, and buffer overflows to provide a comprehensive view of security risks. The content collected covers a wide range of vulnerability types, including injection flaws, insecure default configurations, and path traversal issues. This aggregation spans historical data from the product’s initial releases up to the most recent updates, ensuring that both legacy and contemporary security concerns are addressed. Users can track vendor advisories to stay informed about official patches and mitigation strategies released by JFrog. Additionally, the page allows readers to understand specific weakness classes by examining how they manifest in Artifactory, offering context on severity and potential impact. It also supports looking up a product’s vulnerability history, providing a chronological timeline of discovered issues and their resolution status. This resource is designed for security professionals, developers, and administrators who need to assess the security posture of their Artifactory deployments. By centralizing this information, the page facilitates efficient risk management and informed decision-making regarding software updates and security hardening. The data is sourced from authoritative feeds and verified reports to ensure accuracy and relevance.

Vendor: Jfrog

CVE IDTitleCVSSSeverityPublished
CVE-2026-65922 Potential unauthorized modification of Artifactory internal metadata CWE-862 7.1 High2026-07-27
CVE-2026-65923 Potential server-side request forgery in Artifactory Ansible repository handling CWE-918 6.8 Medium2026-07-27
CVE-2026-65617 Potential remote code execution on an Artifactory package service container. CWE-502 8.8 High2026-07-27
CVE-2026-65924 Server-Side Request Forgery (SSRF) via Terraform Remote repository CWE-918 6.5 Medium2026-07-27
CVE-2026-65925 Server-Side Request Forgery (SSRF) via JFrog Artifactory Cargo remote repository CWE-918 6.5 Medium2026-07-27
CVE-2026-65616 Potential privilege escalation to JFrog administrator privileges CWE-347 8.8 High2026-07-27
CVE-2026-66015 JFrog Platform contains an authorization flaw that may allow authenticated privilege escalation. CWE-269 7.2 High2026-07-27
CVE-2026-65618 Improper URL validation when handling specific URLs Pub, Terraform and Docker packages might lead to SSRF vulnerability CWE-918 6.5 Medium2026-07-27
CVE-2026-66018 JFrog Artifactory build environment properties exposure CWE-200 6.5 Medium2026-07-27
CVE-2026-66014 Potential authentication bypass leading to privilege escalation in Artifactory CWE-287 8.8 High2026-07-27
CVE-2026-65921 Potential path traversal leading to unauthorized file writes CWE-22 8.8 High2026-07-27
CVE-2026-42017 Privilege escalation via JFrog Worker event token exposure CWE-200 8.8 High2026-07-27
CVE-2026-42016 Incorrect authorization validation of user token in JFrog Artifactory allows Privilege Escalation CWE-863 8.1 High2026-07-27
CVE-2024-6915 JFrog Artifactory Cache Poisoning CWE-20 9.3 Critical2024-08-05
CVE-2024-2248 JFrog Artifactory Header Injection CWE-20 6.4 Medium2024-05-15
CVE-2024-4142 JFrog Artifactory Improper input validation within token creation flow CWE-20 9.0 Critical2024-05-01
CVE-2024-2247 JFrog Artifactory Cross-Site Scripting CWE-79 8.8 High2024-03-13
CVE-2023-42509 JFrog Artifactory Sensitive Data Leakage in Repository configuration process CWE-755 6.6 Medium2024-03-07
CVE-2023-42661 JFrog Artifactory Improper input validation leads to arbitrary file write CWE-20 7.2 High2024-03-07
CVE-2023-42662 JFrog Artifactory Improper SSO Mechanism may lead to Exposure of Access Tokens CWE-287 9.3 Critical2024-03-07
CVE-2023-42508 JFrog Artifactory Improper header input validation leads to email manipulation sent from the platform CWE-20 6.5 Medium2023-10-03
CVE-2021-41834 JFrog Artifactory 安全漏洞 CWE-284 5.3 Medium2022-05-23
CVE-2021-45730 JFrog Artifactory 安全漏洞 CWE-284 6.0 Medium2022-05-19
CVE-2019-17444 JFrog Artifactory does not enforce default admin password change CWE-521 9.8 Critical2020-10-12

All 24 known CVE vulnerabilities affecting artifactory with full Chinese analysis, references, and POCs where available.