Impact
The vulnerability allows a Project Resource Manager to acquire broader administrative rights under specific conditions, creating a privilege escalation risk for the Artifactory instance. The weakness is categorized as CWE‑269, which indicates improper authorization. This escalation could enable the attacker to alter or delete repositories, create new users, or modify security settings, potentially compromising the confidentiality, integrity, and availability of the system.
Affected Systems
JFrog Artifactory is affected. No specific product versions were listed in the public information; impacted releases cannot be identified without further version data from the vendor documentation.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity. EPSS was not reported, and the vulnerability is not listed in CISA’s KEV catalog, meaning the likelihood of known exploitation is uncertain. The attack vector is inferred to require the attacker to possess a Project Resource Manager role and identify the precise conditions that trigger privilege elevation; it is not explicitly disclosed in the advisory.
OpenCVE Enrichment