Impact
A repository reader that holds cache‑deploy permission in JFrog Artifactory can retrieve files located outside of an upstream configuration path when interacting with certain upstream repositories. The vulnerability provides a means for an attacker with such a role to read arbitrary files on the Artifactory server that lie beyond the intended upstream boundaries, potentially exposing sensitive configuration, secrets, or user data. The weakness is a classic path traversal based on incorrect validation of upstream path constraints, aligning with CWE‑22.
Affected Systems
The affected product is JFrog Artifactory. No specific version numbers are disclosed in the advisory, so affected installations of any release that has not applied a remedial update may be vulnerable. Administrators should check the product release notes and ensure they are running a patched version.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity for confidentiality impact. Because the EPSS score is unavailable and the vulnerability is not listed in the CISA KEV catalog, the likelihood of widespread exploitation is unknown, but the limited privilege requirement (cache‑deploy role) means that any user granted that role could exploit the flaw. No additional prerequisites or sophisticated attack steps are described, suggesting that exploitation can be carried out directly by the repository reader once the necessary permission exists.
OpenCVE Enrichment