Impact
The vulnerability allows a low-level user to instruct Artifactory to fetch resources from arbitrary remote CocoaPods repositories. This constitutes a server‑side request forgery, enabling an attacker to make outbound HTTP requests from the Artifactory host. While the CVSS score of 3.5 indicates a low severity, the ability to reach external systems could expose sensitive data or facilitate additional attacks if the fetched content is processed by other components.
Affected Systems
The affected product is JFrog Artifactory. No specific versions are listed in the data, so all deployed installations of Artifactory could be susceptible until a vendor‑supplied fix is applied.
Risk and Exploitability
The CVSS score of 3.5 reflects limited impact and low privilege escalation. EPSS data is unavailable, and the vulnerability is not in the CISA KEV catalog, meaning it is not currently known to be widely exploited. The likely attack vector is a local low-level user or compromised account that can invoke Artifactory’s external dependency resolution. Given the constraints, the risk is moderate for environments where Artifactory has unrestricted outbound network access, and priority should be placed on monitoring outbound traffic rather than immediate patching if no fix is available.
OpenCVE Enrichment