Impact
An authenticated user lacking repository read permission can access private NuGet metadata under specific conditions. The vulnerability enables disclosure of information that should only be accessible to authorized users, violating confidentiality requirements. It is a missing authorization flaw, identified as CWE‑862.
Affected Systems
The affected product is JFrog Artifactory. No specific version information is provided in the current data, so the risk applies to releases that contain the identified access control weakness until a patched version is released.
Risk and Exploitability
The CVSS score of 4.3 denotes moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack requires the attacker to be an authenticated user who does not possess repository read permission; the attacker must trigger a request that retrieves metadata for a private NuGet package, which the system incorrectly returns. Because the conditions under which the flaw occurs are not fully described, the likelihood of exploitation is uncertain, though the malicious path is straightforward once authenticated access exists.
OpenCVE Enrichment