Impact
The vulnerability is a URL validation weakness in the Ansible repository handling of JFrog Artifactory. When an attacker with certain repository access rights submits a crafted URL, the server will resolve and request that URL on the server’s behalf. This can lead to unintended data exfiltration or manipulation of internal systems, compromising confidentiality and integrity of the environment.
Affected Systems
The affected product is JFrog Artifactory. No specific version information is provided in the advisory, so all installations that handle Ansible repositories should be reviewed.
Risk and Exploitability
The CVSS score of 6.8 indicates a medium severity risk. The EPSS score is <1%, indicating a very low but nonzero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves a server-side request forgery where an attacker crafts a malicious URL; the effectiveness depends on the repository’s access controls. Because the attack relies on valid access to the repository configuration, the exploitability is moderate, and no public exploit is currently confirmed. The vulnerability has been addressed in fixed Artifactory versions.
OpenCVE Enrichment