Impact
An authorization weakness in JFrog Artifactory allows a user with limited repository access to write to restricted internal metadata areas under specific conditions. The main consequence is low‑level integrity and availability impact; confidentiality remains unaffected.
Affected Systems
The affected product is JFrog Artifactory. No specific version information is disclosed in this advisory; any running instance could be vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 7.1 indicates a high‑severity vulnerability. The EPSS score is 0.00176 (<1%), suggesting a very low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector requires authenticated access with repository permissions, as the threat requires a user to have some level of repository interaction to exploit the weakness. Successful abuse is constrained to modifying internal metadata, so while the impact is moderate, the risk is significant for environments that rely on the integrity of metadata for deployment or security controls.
OpenCVE Enrichment