Description

A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user, under specific repository access conditions, to cause unintended server-side requests. The issue primarily affects confidentiality and integrity and has been addressed in fixed Artifactory versions.

Severity (CVSS)

Base score6.8
SeverityMedium
VersionCVSS 3.1
VectorCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Provided byCNA

Weaknesses

  • CWE-918 — CWE-918 Server-Side Request Forgery (SSRF)

Affected products

VendorProductVersions
jfrogartifactory0 to <7.111.18; 7.117.0 to <7.117.25; 7.125.0 to <7.125.18; 7.133.0 to <7.133.27; 7.146.0 to <7.146.34; 7.161.0 to <7.161.15

References

Authoritative sources

This page is a snapshot. For the latest enrichment and updates, view the record on CVE.org or the NVD.

Generated from the official CVE List on 28 Jul 2026 07:03 UTC.