« Volver al listado

CVE-2026-65923

Estado: AnalizadaMedia (6.8)—

A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user, under specific repository access conditions, to cause unintended server-side requests. The issue primarily affects confidentiality and integrity and has been addressed in fixed Artifactory versions.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-65923",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-65923",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-07-27T19:57:31.667644Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "reefs@jfrog.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.8,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 1.6
      }
    ]
  },
  "affected": [
    {
      "source": "reefs@jfrog.com",
      "affectedData": [
        {
          "vendor": "jfrog",
          "product": "artifactory",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "7.111.18",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "7.117.0",
              "lessThan": "7.117.25",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "7.125.0",
              "lessThan": "7.125.18",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "7.133.0",
              "lessThan": "7.133.27",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "7.146.0",
              "lessThan": "7.146.34",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "7.161.0",
              "lessThan": "7.161.15",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-07-27T20:16:41.433",
  "references": [
    {
      "url": "https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases",
      "tags": [
        "Release Notes"
      ],
      "source": "reefs@jfrog.com"
    },
    {
      "url": "https://docs.jfrog.com/releases/docs/jfrog-security-advisories",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "reefs@jfrog.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "reefs@jfrog.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-918"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user, under specific repository access conditions, to cause unintended server-side requests.\nThe issue primarily affects confidentiality and integrity and has been addressed in fixed Artifactory versions."
    }
  ],
  "lastModified": "2026-07-30T14:44:14.643",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*",
              "vulnerable": true,
              "matchCriteriaId": "151CCEC4-A0A0-496D-A8B7-72506F01A35B",
              "versionEndExcluding": "7.111.18"
            },
            {
              "criteria": "cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*",
              "vulnerable": true,
              "matchCriteriaId": "910195A3-A894-48FF-A34A-26DD34761B19",
              "versionEndExcluding": "7.117.25",
              "versionStartIncluding": "7.117.0"
            },
            {
              "criteria": "cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9D1868C0-C39A-48E2-B409-3695A4C5E42D",
              "versionEndExcluding": "7.125.18",
              "versionStartIncluding": "7.125.0"
            },
            {
              "criteria": "cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5AE54814-899E-4112-B109-13E37CBD22DF",
              "versionEndExcluding": "7.133.27",
              "versionStartIncluding": "7.133.0"
            },
            {
              "criteria": "cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E6A34476-6BAA-4A28-8224-7A1F994A0A07",
              "versionEndExcluding": "7.146.34",
              "versionStartIncluding": "7.146.0"
            },
            {
              "criteria": "cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*",
              "vulnerable": true,
              "matchCriteriaId": "584293DE-36E6-43DD-85BF-4AE115FBD415",
              "versionEndExcluding": "7.161.15",
              "versionStartIncluding": "7.161.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "reefs@jfrog.com"
}