Impact
This vulnerability allows an unauthenticated user to retrieve restricted Artifactory artifacts when a credentialed remote repository is set up in a particular way. The flaw is an Access Control Failure (CWE-862) that permits unauthorized disclosure of content that should be protected. The attack grants access to confidential binary or source artifacts, exposing potentially proprietary or sensitive information to anyone on the network.
Affected Systems
The affected product is JFrog Artifactory, a widely deployed binary repository manager. No specific version numbers were disclosed in the advisory; therefore the vulnerability may affect any Artifactory instance configured with credentialed remote repositories in the described manner.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. Because the EPSS score is unavailable and the flaw is not listed in the CISA KEV catalog, the likelihood of public exploitation is currently unknown. Based on the description, it is inferred that the attack can be performed from any location that can reach the Artifactory server, and it requires only the specific repository configuration—no credentials are needed to trigger the vulnerability. An attacker who successfully exploits the flaw can gain read access to artifacts, although no remote code execution or privilege escalation is reported.
OpenCVE Enrichment