Artifactory can hand an unauthenticated caller a valid anonymous-user token even after anonymous access has been switched off, letting anyone who can reach it read sensitive artefacts.
Posts tagged: JFrog
JFrog Artifactory Incorrect Authorization Vulnerability
Artifactory checks a token’s signature and issuer but not its scope, letting a low-privilege token holder escalate to actions the token was never meant to permit.