Exploited Vulnerabilities Daily
🌐 日本語

← 新着一覧

CVE-2026-66384: JFrog Artifactory

JFrog Artifactory には、制限されたディレクトリの脆弱性に対するパス名の不適切な制限が含まれています。これにより、認証されたユーザーは、特定のリモートリポジトリ条件下で意図した Docker キャッシュパス外にデータを書き込みできます。

CISA (English)

JFrog Artifactory contains an improper limitation of a pathname to a restricted directory vulnerability. This can allow an authenticated user to write data outside the intended Docker cache path under specific remote-repository conditions.

ベンダー
JFrog
製品
Artifactory
脆弱性
JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability
追加日
2026/08/27
CISA対応期限(米国連邦機関向け)
2026/09/10
ランサムウェア攻撃での利用
不明
弱点(CWE)
CWE-22

参考情報

当サイトはCISAのカタログを情報提供のために要約したもので、セキュリティ上の助言ではありません。ベンダーの案内と公式のアドバイザリーに従ってください。

最終更新: · カタログのバージョン 2026.10.02