Impact
The vulnerability allows JFrog Artifactory to return an internal anonymous‑user token to an unauthenticated caller when anonymous access is disabled. This token can be used to read sensitive artifacts or configuration data. The exposed token effectively bypasses authentication controls, giving the caller privileges it should not possess. The weakness is identified as CWE‑287.
Affected Systems
The flaw applies to deployments of JFrog Artifactory where anonymous access is disabled. No specific version is provided, so all releases that expose the token behavior are potentially affected. Administrators should review versions in use and check configuration files noting that the issue occurs even with anonymous access turned off.
Risk and Exploitability
The CVSS score of 7.5 indicates a significant threat. There is no available EPSS or KEV listing, suggesting current exploitation activity is unknown, but the flaw remains exploitable from the network as any unauthenticated client can retrieve the token. Attackers could leverage the token to read or download confidential repositories, making this a critical concern for organizations relying on Artifactory for secure storage.
OpenCVE Enrichment