Jfrog
14 known vulnerabilities
Top Products
An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.
Build readers can access another repository's environment properties. A caller with read access to an ordinary repositor
An authenticated privilege-escalation vulnerability in JFrog Platform may be exploited under admin-provisioned account c
JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific condi
A user with JFrog Artifactory Cargo remote repository read access could make Artifactory request unintended URLs and ret
JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Server-Side Request Forgery (
A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user, under specific repository
An authorization weakness in JFrog Artifactory internal metadata handling could allow a user with limited repository acc
A path validation weakness in archive extraction/write handling allows entries with traversal sequences to be written ou
Improper URL validation when handling specific URLs, allows an attacker, under certain conditions, to make unauthorized
A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact confidentia
Incorrect authorization validation in refresh token signature allows non-admin users to obtain a signed JFrog administra
An event-handling weakness in JFrog Artifactory could expose privileged authorization material to a lower-privileged use
JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a valida
Frequently Asked Questions
How many CVEs affect Jfrog?
Jfrog has 14 CVE records in our database, including 0 critical and 8 high severity vulnerabilities. 1 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Jfrog vulnerabilities?
Jfrog has 0 critical severity (CVSS 9.0+) and 8 high severity (CVSS 7.0-8.9) vulnerabilities. 1 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Jfrog vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Jfrog products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Jfrog Vulnerabilities
CyberStrike scans your infrastructure for Jfrog vulnerabilities and provides real-time remediation guidance.
Get Started