Impact
A low‑privilege authenticated user can permanently delete protected internal metadata for all repositories when certain conditions are met. This compromised data integrity can render repositories unusable or cause them to become corrupted, potentially leading to loss of repository data and service disruption. The weakness is a classic access‑control flaw (CWE‑862).
Affected Systems
The vulnerability affects JFrog Artifactory instances. No version information was supplied, so any installation that has not applied the latest security update could be exposed.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity. While no EPSS score is available, the lack of KEV listing suggests no publicly known exploitation yet. The likely attack vector involves an authenticated user with low privileges who has access to the Artifactory UI or API; the user can exploit the weakness by invoking the metadata deletion feature under the restricted conditions described in the advisory. Because the mistake is an access control issue, an attacker only needs permission to delete metadata, which they can obtain by leveraging existing credentials. The impact is confined to the integrity of repository metadata, but the consequences can be widespread if the metadata is essential for repository operation.
OpenCVE Enrichment