Impact
The vulnerability stems from a missing authorization check that allows an authenticated user who does not have repository read permission to view package metadata under certain conditions. This enables unintended disclosure of internal repository information, potentially revealing artifact details and repository structure. The weakness is a classic missing authorization flaw identified as CWE‑862.
Affected Systems
The affected product is JFrog Artifactory, the enterprise artifact repository manager. No specific versions are listed in the advisory, so all releases of Artifactory could be impacted unless otherwise stated by the vendor.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate impact, and the EPSS score is unavailable, so the likely exploitation probability is unclear. The vulnerability is not listed in CISA KEV. The attack requires an authenticated session, so an attacker must first compromise or obtain valid credentials for a user lacking read rights. Once authenticated, the user can query metadata endpoints to exfiltrate information. Because no remote code execution or denial of service is involved, the threat is primarily information disclosure rather than a full system compromise.
OpenCVE Enrichment