stable

jfrog-cli-2.98.0-1.el9

FEDORA-EPEL-2026-b5304cc714 created by rathann 3 weeks ago for Fedora EPEL 9

This update has been submitted for testing by rathann.

3 weeks ago

This update's test gating status has been changed to 'ignored'.

3 weeks ago

This update has been pushed to testing.

3 weeks ago

This update has been submitted for stable by bodhi.

2 weeks ago

This update has been pushed to stable.

2 weeks ago

Please log in to add feedback.

Metadata
Type
security
Severity
high
Karma
0
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-1
Stable by Karma
1
Stable by Time
7 days
Dates
submitted
3 weeks ago
in testing
3 weeks ago
in stable
2 weeks ago
approved
2 weeks ago
BZ#2403136 CVE-2025-11579 jfrog-cli: RarDecode Out Of Memory Crash [epel-9]
0
0
BZ#2420569 CVE-2025-47913 jfrog-cli: golang.org/x/crypto/ssh/agent: SSH client panic due to unexpected SSH_AGENT_SUCCESS [epel-9]
0
0
BZ#2421867 CVE-2025-66564 jfrog-cli: Sigstore Timestamp Authority: Denial of Service via excessive OID or Content-Type header parsing [epel-9]
0
0
BZ#2432197 CVE-2026-23831 jfrog-cli: Rekor denial of service [epel-9]
0
0
BZ#2433101 CVE-2026-23991 jfrog-cli: go-tuf client DoS via malformed server response [epel-9]
0
0
BZ#2433104 CVE-2026-23992 jfrog-cli: go-tuf improperly validates the configured threshold for delegations [epel-9]
0
0
BZ#2433535 CVE-2026-24117 jfrog-cli: Rekor Server-Side Request Forgery (SSRF) [epel-9]
0
0
BZ#2433572 CVE-2026-24137 jfrog-cli: sigstore legacy TUF client allows for arbitrary file writes with target cache path traversal [epel-9]
0
0
BZ#2434246 CVE-2026-24686 jfrog-cli: go-tuf Path Traversal in TAP 4 Multirepo Client Allows Arbitrary File Write via Malicious Repository Names [epel-9]
0
0
BZ#2452365 CVE-2026-32285 jfrog-cli: github.com/buger/jsonparser: Denial of Service via malformed JSON input [epel-all]
0
0
BZ#2454524 CVE-2026-34165 jfrog-cli: go-git: Denial of Service via crafted .idx file [epel-all]
0
0
BZ#2454525 CVE-2026-33762 jfrog-cli: go-git: Denial of Service via crafted Git index file [epel-all]
0
0
BZ#2455638 CVE-2026-34986 jfrog-cli: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object [epel-all]
0
0

Automated Test Results