Impact
An unauthenticated user can reach repository information that is intended to be restricted, potentially exposing sensitive metadata about Artifactory repositories. The weakness is a missing access control that allows anyone to read certain repository details, as identified by CWE-862.
Affected Systems
The vulnerability affects JFrog Artifactory. No specific product versions are listed in the data, so all deployments of Artifactory may be impacted until a vendor fix is released.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity for this information‑disclosure issue. The EPSS score is not available, so the current exploitation probability is unknown; the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is an unauthenticated HTTP request to a repository information endpoint that is exposed under certain conditions. An attacker would need to access that endpoint, which may or may not be enabled depending on the specific configuration. The impact is limited to confidentiality—no control or integrity impact is described, but the exposure of repository metadata could aid further attacks by revealing the structure of managed artifacts.
OpenCVE Enrichment