JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
How easy to exploit
Severity of consequences
Likelihood of exploitation in next 30 days