Impact
JFrog Artifactory Self‑Hosted releases prior to 7.133.11 incorrectly validate user tokens by checking the signature and issuer but not the scope. This flaw permits an attacker who has a valid token to use it with higher privileges than intended, allowing access to protected artifacts, administrative functions and potentially compromising confidentiality, integrity, and availability of the system. The vulnerability is classified under CWE‑863, denoting an improper authorization weakness.
Affected Systems
All self‑hosted installations of JFrog Artifactory up to version 7.133.11 are affected. The flaw is tied to the token authentication logic used in those releases.
Risk and Exploitability
8.1 signals a high severity vulnerability, and the EPSS score of 9% indicates a moderate exploitation probability. It has now been listed in the CISA KEV catalog, indicating that the vulnerability has been observed in the wild or is considered a known exploit target.
OpenCVE Enrichment