Impact
An authenticated user can write data outside the intended Docker cache path when using specific remote-repository settings, which is a classic path traversal flaw (CWE-22). The vulnerability allows unauthorized modification of files that should be restricted to the cache directory, potentially enabling an attacker to replace or tamper with critical repository artifacts. The direct impact is the ability to alter data in the Artifactory installation, which could affect repository integrity and availability.
Affected Systems
JFrog Artifactory self‑managed installations are impacted. No specific version range is listed, so all releases prior to a remediation that patches the path handling flaw should be considered vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is 0.26% (approx. 0.00264) and the vulnerability is listed in the CISA KEV catalog, suggesting it has not been widely exploited yet. An attacker would need valid credentials and acceptance of the specific remote‑repository configuration to trigger the path traversal.
OpenCVE Enrichment