Impact
A low‑privileged authenticated user may read restricted support information under specific conditions. The likely cause appears to be the absence of an authorization check when serving support data, which allows non‑administrator accounts to access internal diagnostics and configuration details that should be limited to administrators. This information‑disclosure flaw exposes sensitive system information to compromised or low‑privileged users, potentially aiding further attacks.
Affected Systems
JFrog Artifactory is affected. No specific release numbers are cited in the advisory, so any installation of Artifactory that has not yet applied the vendor’s fix may be vulnerable. All users with low‑privileged authenticated access should be considered at risk until the remediation is applied.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog. The flaw is exploitable only after authentication, meaning an attacker must first gain legitimate credentials or otherwise authenticate to a low‑privileged account. Once authenticated, an attacker can target the support endpoint to retrieve privileged information, but there is no evidence of remote code execution or privilege escalation from the available data.
OpenCVE Enrichment