Threat actors have been chaining three JFrog Artifactory vulnerabilities to gain admin privileges and deploy backdoors.
This story is only covered by news sources that have yet to be evaluated by the independent media monitoring agencies we use to assess the quality and reliability of news outlets on our platform. Learn more here.
A 24-day campaign documented by Wiz concatenates three CVEs in JFrog Artifactory to get administrative privileges in less than 5 minutes, install malevolent Groovy plugins and plant persistent backdoors in Rust. Up to 62% of the instances displayed online is vulnerable. The article Five minutes to become admin: the chain of exploits that transforms three JFrog Artifactory bugs into a backdoor Rust comes from (in) digital security.