Impact
The vulnerability is an insecure deserialization condition in JFrog Artifactory, triggered by an attacker who can write to stored session data. By injecting malicious serialized objects the attacker may execute arbitrary code or modify Artifactory data. The weakness is classified as CWE-502, a classic insecure deserialization flaw that can lead to remote code execution, information disclosure or denial of service.
Affected Systems
JFrog Artifactory is the affected product. The CNA identifier jfrog:artifactory covers all Artifactory releases, but no specific version range is provided. Therefore any Artifactory instance that permits a party to write session data may be impacted.
Risk and Exploitability
The CVSS score of 6.6 indicates a medium severity. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, suggesting it is not currently a widely deployed exploit. The attack vector likely requires write access to session data, implying that an attacker must have some level of privileged or trusted access to the Artifactory environment. If exploited, the attacker could run code with the Artifactory process privileges or tamper with stored artifacts.
OpenCVE Enrichment