Impact
An authenticated user who does not have repository read permission can view private OCI referrer metadata when certain conditions are met. The vulnerability arises because the system fails to enforce proper authorization the same way it does for reading repository contents, allowing the attacker to expose potentially sensitive reference relationships between container images. This weakness corresponds to Missing Authorization (CWE‑862).
Affected Systems
The affected product is Jfrog Artifactory. Specific product versions that contain the vulnerability are not listed in the advisory, so administrators should check the vendor release notes for their installed version. The issue applies only to accounts that are authenticated to the Artifactory instance but lack explicit read rights to the target repository.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. Exploit probability is currently unknown because an EPSS value is not available, but the absence of a KEV listing suggests it is not a widely exploited flaw at the time of this analysis. Attackers would need to be authenticated, so the risk is confined to insiders or compromised credentials; nevertheless, the potential information disclosure may aid in further attacks against the organization.
OpenCVE Enrichment