CVE-2026-66384: JFrog Artifactory
JFrog Artifactory包含一個路徑名對限制目錄脆弱性的不當限制。這可以允許經認證的使用者在特定遠端儲存條件下在預定的多克快取路徑外寫入資料。
CISA (English)
JFrog Artifactory contains an improper limitation of a pathname to a restricted directory vulnerability. This can allow an authenticated user to write data outside the intended Docker cache path under specific remote-repository conditions.
- 廠商
- JFrog
- 產品
- Artifactory
- 漏洞
- JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability
- 加入日期
- 2026年8月27日
- CISA 修補期限(美國聯邦機關)
- 2026年9月10日
- 已知用於勒索軟體攻擊
- 未知
- 弱點(CWE)
- CWE-22
參考資料
本站僅為資訊目的整理 CISA 目錄,並非資安建議。請遵循廠商指引與官方公告。
最後更新: · 目錄版本 2026.10.02