Impact
An authentication-based privilege‑escalation flaw in the JFrog Platform enables attackers who already have authenticated access to obtain temporary administrator rights. Listed as CWE‑269, the vulnerability can allow a compromised user to gain full control of the platform, leading to unauthorized configuration changes, data tampering, or further internal exploits. The flaw can be exploited under admin‑provisioned account conditions.
Affected Systems
The flaw is present in the JFrog Artifactory product provided by the vendor JFrog. No specific version information is included in the advisory; it applies to the current self‑managed releases mentioned in the JFrog documentation.
Risk and Exploitability
The CVSS score of 7.2 indicates moderate to high risk, while the EPSS score is less than 1% and the issue is not listed in KEV. Exploitation requires an existing authenticated account that has admin‑provisioned rights. Successful exploitation will grant the attacker temporary platform administrator access.
OpenCVE Enrichment