Impact
A repository publisher that does not have delete permission can, under certain conditions, modify protected package content. This loophole allows such a user to overwrite Docker layer information, effectively tampering with package integrity. The flaw represents an access‑control weakness—CWE-862—where permissions do not prevent unauthorized content changes.
Affected Systems
JFrog Artifactory self‑managed releases are impacted. No specific version range was listed, so any build that includes the standard publisher functionality is potentially vulnerable unless mitigated by permissions.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity. No EPSS data is available, so the likelihood of exploitation is unknown. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector involves internal users with publish rights; an attacker gaining such rights could overwrite protected layers, leading to tampered or malicious images in the repository.
OpenCVE Enrichment