Post

Artifactory vulnerabilities under active exploitation enable authentication bypass and admin access

Wiz reports that attackers are chaining three Artifactory flaws to gain administrator control of exposed self-hosted instances. Two flaws let attackers obtain and elevate an internal anonymous-user token; a third can grant unauthenticated admin access directly. Wiz observed persistent admin accounts, malicious Groovy plugins, stolen credentials and signing keys, and other follow-on activity—including cases where the chain reached admin access in under five minutes.

Patching closes the entry points, but does not remove an attacker or artifacts already planted. Wiz’s advice is to treat an instance exposed while vulnerable as potentially compromised, upgrade, and investigate for persistence and stolen secrets. InfoQ has no article comment section.