CVE-2026-66384: JFrog Artifactory
JFrog Artifactory는 제한된 디렉토리 취약점에 경로를 제한하는 제한을 포함합니다. 이것은 특정한 원격 저장소 상태의 밑에 예정된 도커 시렁 경로 밖에 자료를 쓰기 위하여 정통한 사용자를 허용할 수 있습니다.
CISA (English)
JFrog Artifactory contains an improper limitation of a pathname to a restricted directory vulnerability. This can allow an authenticated user to write data outside the intended Docker cache path under specific remote-repository conditions.
- 공급업체
- JFrog
- 제품
- Artifactory
- 취약점
- JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability
- 추가일
- 2026. 8. 27.
- CISA 조치 기한(미국 연방기관)
- 2026. 9. 10.
- 랜섬웨어 공격 악용
- 알 수 없음
- 약점(CWE)
- CWE-22
참고 자료
이 사이트는 정보 제공 목적으로 CISA 카탈로그를 요약한 것이며 보안 조언이 아닙니다. 공급업체 안내와 공식 권고를 따르세요.
최종 업데이트: · 카탈로그 버전 2026.10.02