Impact
The vulnerability is a missing authorization flaw that lets an authenticated user trigger repository migration tasks in JFrog Artifactory without the required repository permissions. This can expose repository contents, allow unauthorized changes to the artifact store, and cause service disruption. The issue falls under CWE‑862 missing authorization.
Affected Systems
JFrog Artifactory products are impacted. No specific version range is detailed in the advisory, but the vendor notes that fixed versions exist. Any installation that has not yet applied the vendor‑issued patch is potentially affected.
Risk and Exploitability
The CVSS score is 7.6, indicating high severity. EPSS data is unavailable, so the probability of exploitation is unknown, and the vulnerability is not listed in the CISA KEV catalog, meaning no confirmed exploits are documented. The likely attack vector requires an authenticated account with valid credentials; an attacker with such credentials or who has compromised a legitimate user can exploit the flaw. No additional prerequisites beyond authorization are stated in the advisory.
OpenCVE Enrichment