Impact
The vulnerability allows credentials belonging to a user that has been deleted to remain valid for a short period under specific, unspecified conditions. This means that an attacker who knows or can obtain a deleted user’s credentials may continue to authenticate to JFrog Artifactory services, potentially accessing data or performing actions beyond their intended scope. The weakness is tied to improper handling of authentication state after account removal and is classified as CWE‑613.
Affected Systems
JFrog Artifactory (self‑managed releases) is impacted. No particular versions are listed in the advisory, so all current releases should be inspected for this behavior.
Risk and Exploitability
With a CVSS score of 4.2 the issue is considered moderate. The EPSS score is not available, and it is not listed in CISA’s KEV catalog, suggesting that exploitation is not currently widespread but could still pose a risk during the brief window when compromised credentials remain active. The likely attack vector is internal, relying on remaining authentication tokens or cached credentials that are not purged immediately after a user is deleted.
OpenCVE Enrichment