JFrog Artifactory Vulnerabilities Exploited in the Wild
JFrog Artifactory is a software tool that stores and shares company code and files. Attackers found two flaws that let them take over admin accounts and access private company data without a password.
- Severity
- Not scoredNo CVSS score recorded
- Fix
- Fixed in 7.43.11
- Exploited
- Not confirmedNo confirmation recorded
How it works
- Attackers send specially built requests to the Artifactory admin login page.
- The tool does not check if the request is real, so it lets the attacker bypass the password and take control of the admin account.
- Once in, the attacker can see and steal private company files, change settings, and add new users.
What to do
Check your Artifactory version by opening the About page in the admin dashboard. If it is 7.43.10 or earlier, 7.44.9 or earlier, or 7.50.2 or earlier, you are affected. If you are unsure, ask your IT team or check the server logs for the version number.
Update Artifactory to version 7.43.11, 7.44.10, or 7.50.3 immediately. Log in to your JFrog account, go to the Downloads section, and install the latest patch. After updating, verify the version in the About page again to confirm the fix.
Technical details
An attacker sends a fake login request to an unpatched Artifactory server. The server accepts it as a real login and gives the attacker full admin access. The attacker then downloads private company files and changes server settings to hide their activity.
Wiz detected JFrog Artifactory vulnerabilities exploited in the wild. Patch JFrog Artifactory vulnerabilities now to stop remote administrative takeovers.