CVE-2026-42018: JFrog Artifactory
JFrog Artifactory包含著一種不適當的認證脆弱性,當匿名訪問被禁用時,可以將內部匿名使用者的代號還給一個未經認證的呼叫者,這有可能暴露敏感資源。
CISA (English)
JFrog Artifactory contains an improper authentication vulnerability that could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
- 廠商
- JFrog
- 產品
- Artifactory
- 漏洞
- JFrog Artifactory Improper Authentication Vulnerability
- 加入日期
- 2026年9月11日
- CISA 修補期限(美國聯邦機關)
- 2026年9月25日
- 已知用於勒索軟體攻擊
- 未知
- 弱點(CWE)
- CWE-287
參考資料
本站僅為資訊目的整理 CISA 目錄,並非資安建議。請遵循廠商指引與官方公告。
最後更新: · 目錄版本 2026.10.02