Executive brief
JFrog Artifactory, a platform for managing software packages and dependencies, contains a security flaw in how it handles Ansible repositories. An attacker with basic user access could exploit this weakness to force the server to make unauthorized requests to internal or external systems. This could lead to the exposure of sensitive internal data or the unauthorized modification of system information.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in JFrog Artifactory's Ansible repository handling component due to a URL validation weakness (CWE-918). An authenticated attacker with low privileges (PR:L) can exploit this flaw under specific repository access conditions to trigger unintended server-side requests. The attack requires high complexity (AC:H) but can result in significant impacts on confidentiality and integrity by allowing the attacker to probe internal network resources or interact with internal services that are not otherwise reachable. The issue has been addressed in several maintenance releases, including versions 7.111.18, 7.117.25, 7.125.18, 7.133.27, 7.146.34, and 7.161.15.
Affected products
- JFrog Artifactory < 7.111.18, 7.117.0 to < 7.117.25, 7.125.0 to < 7.125.18, 7.133.0 to < 7.133.27, 7.146.0 to < 7.146.34, 7.161.0 to < 7.161.15
Timeline
- 2026-07-27: disclosed
- 2026-07-27: advisory
- 2026-07-27: patched