CVE-2026-42018: JFrog Artifactory
JFrog Artifactoryには、匿名アクセスが無効になったときに、内部の匿名ユーザートークンを未認証の発信者に返すことができる不適切な認証脆弱性が含まれているため、潜在的に機密リソースを公開しています。
CISA (English)
JFrog Artifactory contains an improper authentication vulnerability that could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
- ベンダー
- JFrog
- 製品
- Artifactory
- 脆弱性
- JFrog Artifactory Improper Authentication Vulnerability
- 追加日
- 2026/09/11
- CISA対応期限(米国連邦機関向け)
- 2026/09/25
- ランサムウェア攻撃での利用
- 不明
- 弱点(CWE)
- CWE-287
参考情報
当サイトはCISAのカタログを情報提供のために要約したもので、セキュリティ上の助言ではありません。ベンダーの案内と公式のアドバイザリーに従ってください。
最終更新: · カタログのバージョン 2026.10.02