Impact
A holder of a valid integration credential may impersonate other users in JFrog Artifactory under specific conditions. This flaw allows unauthorized actions that would normally require the impersonated user's permissions, leading to potential unauthorized access, modification, or deletion of resources. The vulnerability is classed as CWE-347, which denotes improper restriction of authentication and permits identity spoofing.
Affected Systems
JFrog Artifactory is the affected product. No specific product version is listed in the CNA data, so all current and prior Artifactory releases may be vulnerable until a patch is applied.
Risk and Exploitability
The CVSS severity is 7.2, indicating a high risk potential. EPSS data is not available, and the vulnerability is not listed in CISA KEV, implying no confirmed exploitation reports yet. The likely attack vector is an authenticated integration credential holder; the attacker must obtain or possess a valid credential and then trigger the conditions that allow impersonation, though exact triggering parameters are not disclosed.
OpenCVE Enrichment