Impact
The vulnerability allows a user with read access to a remote VCS repository to replace the repository’s origin or supply an absolute VCS data URL. This manipulation enables the artifact manager to issue HTTP requests to arbitrary destinations, constituting a Server‑Side Request Forgery. The impact can include unauthorized data access, potential exposure of internal network resources, and in worst‑case scenarios, execution of unintended commands or code on the Artifactory host. The weakness is classified as CWE‑918.
Affected Systems
The affected product is JFrog Artifactory, a self‑managed binary repository manager. No specific version information is disclosed in the advisory, so all installations of the product should be reviewed for updates.
Risk and Exploitability
The CVSS score of 8.5 indicates a high severity vulnerability. The EPSS score is not available, and the issue is not present in the CISA KEV catalog. The likely exploit path requires a user who can read the remote VCS repository, which suggests that attackers with legitimate read privileges can trigger the SSRF. Due to the lack of a known exploit in public feeds, the likelihood of exploitation is uncertain, but the high severity warrants timely remediation.
OpenCVE Enrichment