Impact
The reported flaw allows an unauthenticated attacker to manipulate the caching layer of JFrog Artifactory, resulting in the storage of untrusted package content. This compromise can invalidate artifact integrity and may disrupt repository availability under the conditions described, a weakness mapped to CWE-345.
Affected Systems
The vulnerability is relevant to JFrog Artifactory software. No specific version information is provided, so all installations of the product could be potentially impacted until a patch is applied.
Risk and Exploitability
The CVSS score of 8.1 signals high severity. While the EPSS score is not available, the attack does not require authentication, indicating that any network‑accessible Artifactory instance could be abused. Based on the description, it is inferred that an attacker can send crafted package requests to the Artifactory API, causing malicious or accidental content to be cached and used by downstream consumers. The lack of KEV listing does not eliminate the risk of exploitation.
OpenCVE Enrichment