CVE-2026-42018: JFrog Artifactory
JFrog Artifactory는 익명 액세스를 비활성화 할 때 내부 익명 사용자 토큰을 unauthenticated caller로 반환 할 수있는 부적절한 인증 취약점을 포함합니다. 잠재적으로 민감한 리소스를 폭발.
CISA (English)
JFrog Artifactory contains an improper authentication vulnerability that could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
- 공급업체
- JFrog
- 제품
- Artifactory
- 취약점
- JFrog Artifactory Improper Authentication Vulnerability
- 추가일
- 2026. 9. 11.
- CISA 조치 기한(미국 연방기관)
- 2026. 9. 25.
- 랜섬웨어 공격 악용
- 알 수 없음
- 약점(CWE)
- CWE-287
참고 자료
이 사이트는 정보 제공 목적으로 CISA 카탈로그를 요약한 것이며 보안 조언이 아닙니다. 공급업체 안내와 공식 권고를 따르세요.
최종 업데이트: · 카탈로그 버전 2026.10.02