Impact
An authentication weakness in JFrog Artifactory Composer repository handling allows an authenticated user, when specific conditions are met, to read metadata of packages stored in private repositories to which they do not have authorization. This results in confidentiality loss without affecting integrity or availability. The vulnerability is based on inadequate authorization checks and is classified as CWE‑862.
Affected Systems
JFrog Artifactory’s Composer repository feature is impacted. Users who have normal authenticated access to the Artifactory instance may be able to read private package metadata. The exact software versions affected are not listed, but a fix has been issued in later releases.
Risk and Exploitability
The CVSS base score of 6.5 indicates a moderate risk level. EPSS information is not available, but the vulnerability is not listed in CISA KEV, suggesting that widespread exploitation has not been observed. An attacker would need valid authenticated credentials and the specific conditions that trigger the flaw; no privileged escalation is required. Given the moderate CVSS and lack of known exploitation, the risk is significant for organizations that expose sensitive package metadata.
OpenCVE Enrichment