Description

A user with JFrog Artifactory Cargo remote repository read access could make Artifactory request unintended URLs and return the response.

Severity (CVSS)

Base score6.5
SeverityMedium
VersionCVSS 3.1
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Provided byCNA

Weaknesses

  • CWE-918 — CWE-918 Server-Side Request Forgery (SSRF)

Affected products

VendorProductVersions
jfrogartifactory0 to <7.111.18; 7.117.0 to <7.117.25; 7.125.0 to <7.125.18; 7.133.0 to <7.133.27; 7.146.0 to <7.146.34; 7.161.0 to <7.161.15

References

Authoritative sources

This page is a snapshot. For the latest enrichment and updates, view the record on CVE.org or the NVD.

Generated from the official CVE List on 28 Jul 2026 07:03 UTC.