CyberRota Analysis
AI-GeneratedAn authorization weakness in JFrog Artifactory's handling of Composer repositories allows authenticated users to potentially access package metadata from unauthorized repositories, compromising confidentiality. Organizations using affected versions of Artifactory should prioritize applying the available fixes to mitigate this risk. This vulnerability is particularly relevant for teams managing sensitive package data and access controls within their development environments.
Original NVD Description
An authorization weakness in JFrog Artifactory Composer repository handling may allow an authenticated user, under specific conditions, to read package metadata from repositories they are not authorized to read. The issue affects confidentiality and has been addressed in fixed Artifactory versions.