Anonymous user token generation exposure in JFrog Artifactory
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
JFrog Artifactory incorrectly generates and reveals an internal anonymous-user token to unauthenticated users even when anonymous access is supposed to be disabled. This token can be misused to access sensitive resources that should be protected.
When anonymous access is disabled, JFrog Artifactory fails to properly enforce authentication checks and returns an internal anonymous-user token to unauthenticated callers (CWE-287: Improper Authentication). An attacker can obtain this token and use it to access protected resources, bypassing intended access controls. The vulnerability affects availability and confidentiality of restricted artifacts.