Impact
The vulnerability permits a build reader with read access to an ordinary repository to retrieve environment properties for a protected build, revealing build environment secrets that should otherwise remain confidential. This exposure is a direct confidentiality impact and no integrity or availability effects have been demonstrated. It results from improper restriction of read permissions on build environment parameters across repositories.
Affected Systems
JFrog Artifactory is affected; any installation that exposes protected build environment properties to users with ordinary repository read access could be impacted. No specific version information is listed, so all released versions of Artifactory that support build environment properties should be considered potentially vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. EPSS score < 1% and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation evidence yet. Attackers need only read permission on a non-protected repository; they can then request environment properties for a protected build and obtain secrets. The likely attack vector is remote through the Artifactory API or web interface, and the vulnerability does not require elevated privileges beyond those read rights.
OpenCVE Enrichment