CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7066

As cited

Copy frozen at (site build).

vulnerabilities

Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors

Attackers exploited two chained vulnerabilities in JFrog Artifactory between August 15 and September 8 to gain administrator control of self-hosted instances and install backdoors, according to research from Wiz. The flaws had been patched by JFrog before the attacks occurred, leaving only unpatched servers vulnerable.

Why it matters: Organizations running self-hosted JFrog Artifactory must verify they applied the patches to prevent attackers from achieving admin access and establishing persistent backdoors in their software supply chain infrastructure.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors

Attackers exploited two chained vulnerabilities in JFrog Artifactory between August 15 and September 8 to gain administrator control of self-hosted instances and install backdoors, according to research from Wiz. The flaws had been patched by JFrog before the attacks occurred, leaving only unpatched servers vulnerable.

Why it matters: Organizations running self-hosted JFrog Artifactory must verify they applied the patches to prevent attackers from achieving admin access and establishing persistent backdoors in their software supply chain infrastructure.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors

Attackers exploited two chained vulnerabilities in JFrog Artifactory between August 15 and September 8 to gain administrator control of self-hosted instances and install backdoors, according to research from Wiz. The flaws had been patched by JFrog before the attacks occurred, leaving only unpatched servers vulnerable.

Why it matters: Organizations running self-hosted JFrog Artifactory must verify they applied the patches to prevent attackers from achieving admin access and establishing persistent backdoors in their software supply chain infrastructure.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary