Impact
The vulnerability allows an unauthenticated user to retrieve restricted artifacts when specific conditions are met. This disclosure can lead to confidentiality breaches by exposing proprietary or sensitive binaries, configuration files, or metadata that should only be available to authorized personnel. It represents an access control weakness (CWE-862).
Affected Systems
Version information is not specified in the CNA data, so any instance of JFrog Artifactory that uses the affected code paths could be vulnerable. Administrators should verify whether their deployments rely on the affected components and consult the JFrog documentation for the relevant release notes.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate overall risk. No EPSS score is available, so current exploitation likelihood is unclear. The vulnerability is not yet listed in the CISA KEV catalog, suggesting no confirmed public exploits. The attack vector involves unauthenticated network access under certain conditions, but details are omitted in the description. Due to the lack of a publicly documented exploit, organizations should treat this as a moderate threat pending further information.
OpenCVE Enrichment