Impact
The vulnerability allows an anonymous or low‑privilege authenticated user to discover the names and versions of private Release Bundles when the bundle name is already known. This results in the disclosure of potentially confidential metadata, compromising the confidentiality of the released artifacts. The weakness is a missing authorization check, classified as CWE‑862.
Affected Systems
Affected product is JFrog Artifactory, specifically the self‑managed release bundles component. No specific version information is listed in the CNA data, so all generally released Artifactory instances that expose private release bundles with anonymous or low‑privilege access are potentially impacted.
Risk and Exploitability
The CVSS score of 3.1 indicates low severity. With EPSS not available and the vulnerability not listed in CISA KEV, the likelihood of widespread exploitation appears modest, yet the information disclosed could be valuable to an attacker. Without the bundle name, the flaw offers minimal direct impact, but once an attacker knows a bundle name they can enumerate its version. Attackers could reach the endpoint via any exposed Artifactory instance that permits anonymous or low‑privilege access.
OpenCVE Enrichment