Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors
Overview
Attackers have exploited two vulnerabilities in JFrog Artifactory, a tool used to manage software packages for build pipelines, to gain admin access to self-hosted servers. This allowed them to install backdoors, enabling ongoing access and control. The attacks were observed between August 15 and September 8, but JFrog had already patched the vulnerabilities prior to the attacks. Therefore, only those servers that had not yet been updated were at risk. This incident underscores the importance of timely software updates, as failure to do so can leave systems vulnerable to exploitation by malicious actors. Organizations using JFrog Artifactory should ensure they are running the latest version to protect against these types of attacks.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: JFrog Artifactory (self-hosted servers)
- Action Required: Update to the latest version of JFrog Artifactory to close the vulnerabilities.
- Timeline: Disclosed on September 8, 2023
Original Article Summary
Attackers have chained two flaws in JFrog Artifactory, the repository that software build pipelines pull from, to take administrator control of self-hosted servers and plant backdoors, cloud security company Wiz said in a report. Wiz saw the attacks between August 15 and September 8. JFrog had fixed both flaws before then, so only servers that had not been updated were open to them.
Impact
JFrog Artifactory (self-hosted servers)
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Disclosed on September 8, 2023
Remediation
Update to the latest version of JFrog Artifactory to close the vulnerabilities.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Vulnerability.