Artifactory flaws chained in attacks deploying backdoor malware
JFrog Artifactory is a software tool that stores and shares company code packages. Attackers found two flaws in it that let them break in, take control, and install a hidden program that steals data or spies on users.
- Report priority
- High
How it works
- Attackers send a special request to an unpatched Artifactory server to break its security rules.
- The server then lets them log in without a password, run commands as an admin, and install a Rust backdoor.
- The backdoor hides on the server and can steal files or send data to the attacker's servers.
What to do
If you run JFrog Artifactory on your own servers, check your version by opening the Artifactory web interface and looking in the app for the version number. Compare it against 7.5.13, 7.6.11, or 7.7.3. If your version is older than these, you are affected.
Update Artifactory to version 7.5.13, 7.6.11, or 7.7.3 immediately. Check the JFrog support site for the update instructions. After updating, log in to Artifactory and confirm the version has changed. If you cannot update, contact JFrog support for help.
Technical details
Attackers sent a fake update request to a company's Artifactory server. The server accepted it, let them log in as an admin, and installed a backdoor that sent stolen files to the attacker's servers.
Threat actors are exploiting critical and high-severity vulnerabilities in JFrog Artifactory to bypass authentication, gain administrative privileges, and deploy a Rust backdoor on vulnerable self-hosted servers.