Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. JFrog/
  3. JFrog Advanced Security

JFrog Advanced Security

AI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Secure coding rating: 0/100How this score is computedA product with no known CVEs starts at a neutral score and climbs the longer it goes without one; a product with known CVEs is penalized by severity instead. This one has 43 known CVEs (vendor-level match — see the CVE list below) and is tracked as ~39 days old in our catalog (a stand-in for real release date, which we don't track). The platform admin controls the formula's weights.

App security testing platform with SAST, SCA, secrets detection, and IaC scanning

by JFrog · jfrog.com · source ↗

Known CVEs (43)14 newAbout this listSourced from the public NVD database, matched by vendor name. Shown here at the vendor level — we don't track per-product/version data, so a listed CVE may affect a different product from this vendor, not necessarily this one. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2026-42018 ↗HIGH 7.5new2026

    JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.

  • CVE-2026-69107 ↗MEDIUM 5.9new2026

    An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions.

  • CVE-2026-68756 ↗MEDIUM 6.6new2026

    A party with write access to stored session data may affect JFrog Artifactory under specific conditions.

  • CVE-2026-66015 ↗HIGH 7.2new2026

    An authenticated privilege-escalation vulnerability in JFrog Platform may be exploited under admin-provisioned account conditions. Successful exploitation may grant temporary platform administrator ac…

  • CVE-2026-66014 ↗HIGH 8.8new2026

    JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access l…

  • CVE-2026-65925 ↗MEDIUM 6.5new2026

    A user with JFrog Artifactory Cargo remote repository read access could make Artifactory request unintended URLs and return the response.

  • CVE-2026-65924 ↗MEDIUM 6.5new2026

    JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Server-Side Request Forgery (SSRF). An authenticated user - or, if anonymous access is enabled on the reposit…

  • CVE-2026-65923 ↗MEDIUM 6.8new2026

    A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user, under specific repository access conditions, to cause unintended server-side requests. The issue primaril…

  • CVE-2026-65922 ↗HIGH 7.1new2026

    An authorization weakness in JFrog Artifactory internal metadata handling could allow a user with limited repository access to write to restricted internal metadata areas under specific conditions. Su…

  • CVE-2026-65618 ↗MEDIUM 6.5new2026

    Improper URL validation when handling specific URLs, allows an attacker, under certain conditions, to make unauthorized requests from JFrog Artifactory, potentially exposing internal services and cach…

  • CVE-2026-65617 ↗HIGH 8.8new2026

    A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact confidentiality, integrity, and availability under specific repository conditions.

  • CVE-2026-65616 ↗HIGH 8.8new2026

    Incorrect authorization validation in refresh token signature allows non-admin users to obtain a signed JFrog administrator token.

  • CVE-2026-42017 ↗HIGH 8.8new2026

    An event-handling weakness in JFrog Artifactory could expose privileged authorization material to a lower-privileged user under specific conditions.

  • CVE-2026-42016 ↗HIGH 8.1new2026

    JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.

  • CVE-2025-14830 ↗MEDIUM 4.92026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in JFrog Artifactory (Workers) allows Cross-Site Scripting (XSS).This issue affects Artifactor…

  • CVE-2024-6915 ↗CRITICAL 9.32024

    JFrog Artifactory versions below 7.90.6, 7.84.20, 7.77.14, 7.71.23, 7.68.22, 7.63.22, 7.59.23, 7.55.18 are vulnerable to Improper Input Validation that could potentially lead to cache poisoning.

  • CVE-2024-2248 ↗MEDIUM 6.42024

    A Header Injection vulnerability in the JFrog platform in versions below 7.85.0 (SaaS) and 7.84.7 (Self-Hosted) may allow threat actors to take over the end user's account when clicking on a specially…

  • CVE-2024-4142 ↗CRITICAL 9.02024

    An Improper input validation vulnerability that could potentially lead to privilege escalation was discovered in JFrog Artifactory. Due to this vulnerability, users with low privileges may gain admin…

  • CVE-2024-3505 ↗MEDIUM 4.32024

    JFrog Artifactory Self-Hosted versions below 7.77.3, are vulnerable to sensitive information disclosure whereby a low-privileged authenticated user can read the proxy configuration. This does not affe…

  • CVE-2024-2247 ↗HIGH 8.82024

    JFrog Artifactory versions below 7.77.7, 7.82.1, are vulnerable to DOM-based cross-site scripting due to improper handling of the import override mechanism.

  • …and 23 more

Materials

0

No datasheets, whitepapers, case studies, videos, or demos linked yet.

Other Application Security (ASPM) products

see all →
  • AI SAST · Arnica
  • Acunetix Web Application & API Security · Acunetix
  • Adronite · Adronite
  • Almanax · Almanax
  • Amplify Security Fix Your Code · Amplify Security
  • Anchore Anchore Enterprise · Anchore
  • Apiiro AI SAST · Apiiro
  • Apiiro ASPM Platform · Apiiro