Executive brief
JFrog Artifactory is a widely-used artifact management platform that stores and manages software packages and dependencies. This vulnerability allows authenticated users to read package metadata from repositories they should not have access to, potentially exposing sensitive information about internal packages and their versions. While authentication is required, the impact is a breach of confidentiality through unauthorized metadata disclosure.
Technical details
The vulnerability is an authorization bypass in the Composer package repository handling logic within Artifactory. An authenticated user can circumvent repository-level access controls under specific conditions to read package metadata from repositories they are not authorized to access. The attack requires valid authentication credentials but does not require elevated privileges. The vulnerability affects confidentiality by allowing unauthorized disclosure of package names, versions, and associated metadata. Fixes are available in Artifactory versions 7.161.12 and later, and 7.146.36 and later.
Affected products
- JFrog Artifactory 7.161.0 to 7.161.11, 7.146.0 to 7.146.35
Timeline
- 2026-08-25: disclosed