Impact
Improper URL validation in JFrog Artifactory allows an attacker who can submit a malicious URL to the system to cause Artifactory to fetch that URL as if from the host machine. This Server Side Request Forgery flaw could expose internal services or endpoints that are normally hidden behind firewalls, and any cached response data returned by Artifactory may also be leaked to the attacker. The vulnerability is categorized as CWE‑918.
Affected Systems
JFrog Artifactory self‑managed releases (any version before the recent patch). No specific affected product versions are listed in the advisory.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. The EPSS score is less than 1 %, suggesting a low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is remote; an attacker must be able to reach Artifactory and submit a crafted URL, which Artifactory will then resolve and connect to from the host environment. Successful exploitation would depend on Artifactory’s ability to reach the target URL internally, making outbound network access a prerequisite.
OpenCVE Enrichment