$ techbeacon▋
Darkweb

Supply‑Chain Breach: Exploits in JFrog Artifactory Grant Attackers Administrator Access

Supply‑Chain Breach: Exploits in JFrog Artifactory Grant Attackers Administrator Access

Cloud‑security firm Wiz disclosed that cyber‑criminals have combined two separate vulnerabilities in JFrog Artifactory to obtain full administrator control over self‑hosted instances and embed persistent backdoors.

The attacks, first observed on August 15, targeted the artifact repository that many development teams rely on to store binaries and container images used in continuous integration and delivery pipelines. By chaining the flaws, the adversaries were able to bypass authentication mechanisms, elevate privileges, and ultimately gain unrestricted access to the underlying server environment.

According to Wiz, the first vulnerability allowed unauthenticated users to interact with the Artifactory API in a way that revealed internal configuration details. The second flaw involved improper validation of input parameters, which the attackers leveraged to execute arbitrary commands as the Artifactory service account. When used together, the bugs formed a reliable path to the administrative console.

Once inside, the threat actors installed backdoors that could be invoked later to re‑enter the compromised systems without detection. The persistence mechanisms were designed to survive routine restarts and updates, raising concerns for organizations that host Artifactory on-premises and may not have robust monitoring in place.

Jenkins, GitLab, and other CI/CD tools often pull dependencies directly from Artifactory, meaning that a breach of the repository can cascade through the software supply chain. Security experts warn that malicious code could be injected into legitimate builds, potentially reaching downstream customers and end users.

Wiz recommends that administrators apply the patches released by JFrog immediately, audit all privileged accounts, and review network traffic for signs of unauthorized access. The company also advises a review of any custom scripts or plugins that interact with the Artifactory API, as these could be exploited if left unpatched. As the investigation continues, organizations are urged to treat the incident as a reminder of the critical importance of timely vulnerability management in software supply‑chain components.

Deepak Chandra Meena — Deepak covers the dark web and underground hacking forums, reporting on marketplace activity and access broker listings. Monitors Tor-based forums and encrypted leak channels.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related