AI description
Automated description summarized from trusted sources.
CVE-2026-65617 describes a deserialization weakness identified within the JFrog Artifactory package handling system. This vulnerability could potentially allow a low-privileged user to impact the confidentiality, integrity, and availability of the system under specific repository conditions. This weakness has been publicly associated with a "potential remote code execution on an Artifactory package service container." It was among several vulnerabilities discovered by OpenAI and subsequently patched by JFrog in Artifactory versions 7.161.15 and 7.146.34.
- Description
- A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact confidentiality, integrity, and availability under specific repository conditions.
- Source
- reefs@jfrog.com
- NVD status
- Analyzed
- Products
- artifactory
CVSS 3.1
- Type
- Secondary
- Base score
- 8.8
- Impact score
- 5.9
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
- reefs@jfrog.com
- CWE-502
- Hype score
- Not currently trending
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*",
"matchCriteriaId": "151CCEC4-A0A0-496D-A8B7-72506F01A35B",
"versionEndExcluding": "7.111.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*",
"matchCriteriaId": "910195A3-A894-48FF-A34A-26DD34761B19",
"versionEndExcluding": "7.117.25",
"versionStartIncluding": "7.117.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*",
"matchCriteriaId": "9D1868C0-C39A-48E2-B409-3695A4C5E42D",
"versionEndExcluding": "7.125.18",
"versionStartIncluding": "7.125.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*",
"matchCriteriaId": "5AE54814-899E-4112-B109-13E37CBD22DF",
"versionEndExcluding": "7.133.27",
"versionStartIncluding": "7.133.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*",
"matchCriteriaId": "E6A34476-6BAA-4A28-8224-7A1F994A0A07",
"versionEndExcluding": "7.146.34",
"versionStartIncluding": "7.146.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*",
"matchCriteriaId": "584293DE-36E6-43DD-85BF-4AE115FBD415",
"versionEndExcluding": "7.161.15",
"versionStartIncluding": "7.161.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]