Impact
A user with read access to a JFrog Artifactory Cargo remote repository can cause Artifactory to request arbitrary URLs and return the response to the user. This use of the repository interface enables a Server‑Side Request Forgery that allows the attacker to discover internal network services, exfiltrate data, or proxy further attacks. The weakness is an input validation flaw, classified as CWE‑918.
Affected Systems
The affected product is JFrog Artifactory for self‑managed installations. No specific version ranges are disclosed; therefore any installation that grants read permissions on a Cargo remote repository may be vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. An EPSS score of < 1 % suggests a very low but non‑zero probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalogue, implying no known public exploits. The likely attack vector is the web API that processes repository read requests; cloning or triggering a read operation provides the attacker with the ability to drive Artifactory to arbitrary destinations.
OpenCVE Enrichment