공격자들이 JFrog Artifactory의 취약점을 이용해 관리 권한을 탈취하고 백도어를 심었다.
공격자들이 JFrog Artifactory에서 두 가지 취약점을 연결하여 자가 호스팅 서버의 관리자 권한을 탈취하고 백도어를 심었다는 보고가 있다. 클라우드 보안 회사인 Wiz에 따르면, 이러한 공격은 8월 15일부터 9월 8일 사이에 발생했으며, JFrog은 이 취약점들을 그 이전에 수정했다. 따라서 업데이트되지 않은 서버만 공격에 노출되었다.
Attackers exploited vulnerabilities in JFrog Artifactory to gain admin access and plant backdoors.
Attackers have chained two vulnerabilities in JFrog Artifactory to take administrator control of self-hosted servers and plant backdoors, according to a report from cloud security company Wiz. The attacks occurred between August 15 and September 8, and JFrog had already patched the flaws prior to that timeframe. As a result, only servers that had not been updated were vulnerable.