Impact
A low‑privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers to retrieve untrusted content. The weakness is an input validation flaw (CWE‑20) that allows malicious manipulation of cached data, leading to trust and integrity violations in downstream consumers.
Affected Systems
The vulnerability affects JFrog Artifactory self‑managed releases. No specific version information is provided in the advisory; any installation that could allow low‑privileged modification of cached metadata is potentially impacted.
Risk and Exploitability
The CVSS score of 8.8 indicates a high‑severity issue. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an insider or compromised low‑privilege user within the Artifactory environment who can modify cached metadata. Successful exploitation would result in the distribution of tampered or malicious artifacts to consumers.
OpenCVE Enrichment