वीकनेस
JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.
प्रभावित प्रोडक्ट
- jfrog artifactory
संदर्भ
- https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases
- https://docs.jfrog.com/releases/docs/jfrog-security-advisories
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-42016
- https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201
हमलावर से पहले बग आप ढूँढें।
GitHub से साइन इन करें और एक मिनट से भी कम में अपना पहला ऑडिट चलाएँ। फ़्री प्लान के लिए क्रेडिट कार्ड की ज़रूरत नहीं।