Impact
A bundle writer can create misleading release promotion information when certain conditions are met, potentially causing the system to record or display incorrect release data. This flaw lets an attacker corrupt the integrity of release records, which may lead to failed deployments, audit failures, or other operational issues. The weakness is a permission management error, as identified by CWE‑863.
Affected Systems
The vulnerability affects the JFrog Artifactory product from JFrog. No specific version information is available in the CNA or the advisory, so all installations of Artifactory that allow bundle writing should be considered potentially impacted.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate risk profile. Because the EPSS score is not available, the likelihood of exploitation is uncertain, but the vulnerability is not currently listed in the CISA KEV catalog. The attack requires the ability to act as a bundle writer, implying that a malicious actor would need some privileged access or would exploit a way to inject a bundle. Under those conditions, the vulnerability could be used to inject false promotion data. The exploit is not trivially available and would require a pre‑existing activity or compromise to reach the bundle writer role.
OpenCVE Enrichment