Impact
This vulnerability allows a highly privileged local user to read generated TLS private keys that are inadvertently included in rendered Helm manifests for Artifactory. By obtaining these keys, the user can decrypt traffic, impersonate Artifactory services, or compromise the confidentiality and integrity of secure communications.
Affected Systems
The affected product is JFrog Artifactory, deployed via self‑managed Helm charts. No specific affected versions were given, so any Artifactory installation using the vulnerable Helm configuration may be impacted.
Risk and Exploitability
The CVSS score of 6.7 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV. The attack surface appears to be local privileged users; an attacker would need access to the host as a user with read permission to the rendered manifest files.
OpenCVE Enrichment