CVE-2026-66384: JFrog Artifactory
JFrog Artifactory には、制限されたディレクトリの脆弱性に対するパス名の不適切な制限が含まれています。これにより、認証されたユーザーは、特定のリモートリポジトリ条件下で意図した Docker キャッシュパス外にデータを書き込みできます。
CISA (English)
JFrog Artifactory contains an improper limitation of a pathname to a restricted directory vulnerability. This can allow an authenticated user to write data outside the intended Docker cache path under specific remote-repository conditions.
- ベンダー
- JFrog
- 製品
- Artifactory
- 脆弱性
- JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability
- 追加日
- 2026/08/27
- CISA対応期限(米国連邦機関向け)
- 2026/09/10
- ランサムウェア攻撃での利用
- 不明
- 弱点(CWE)
- CWE-22
参考情報
当サイトはCISAのカタログを情報提供のために要約したもので、セキュリティ上の助言ではありません。ベンダーの案内と公式のアドバイザリーに従ってください。
最終更新: · カタログのバージョン 2026.10.02