Impact
The vulnerability allows an unauthenticated user to bypass authentication when certain cache conditions are present, potentially giving that user access to protected resources. The weakness maps to CWE‑287, which concerns improper verification of user identity or insufficient authentication. This flaw could compromise confidentiality by allowing arbitrary access to repositories, but it does not indicate remote code execution or denial of service. The described impact is limited to misidentified users who exploit the cache state.
Affected Systems
The affected product is JFrog Artifactory. No specific version details are supplied in the advisory, so any installation that could encounter the cache‑related bypass must be reviewed. The vendor driving this issue is JFrog under their Artifactory portfolio.
Risk and Exploitability
The CVSS score of 5.3 suggests moderate risk, while the EPSS score is not available, meaning the exploitation probability is unclear. The issue is not listed in the CISA KEV catalog, indicating it is not a known widely exploited vulnerability at this time. The likely attack vector is an unauthenticated request that triggers a cache condition; therefore the vulnerability could be utilized remotely if the attacker can reach the Artifactory instance over the network. The evidence for exploitation conditions is derived directly from the advisory, which notes the need for specific cache behavior.
OpenCVE Enrichment