JFrog Artifactory Flaws Enable Software Supply Chain Attacks
ID: 6d677d4b-3562-576a-aec0-7c7c86bb5f52
STIX ID: report--6d677d4b-3562-576a-aec0-7c7c86bb5f52
Feed Name: Infosecurity Magazine (News)
Two vulnerabilities in JFrog Artifactory (CVE-2026-69106, CVSS 8.8; and CVE-2026-65922, CVSS 5.4) allow attackers—potentially anonymous or low-privileged—to manipulate generated package metadata and poison shared caches by abusing unvalidated X-Orig-Client-Uri/X-Forwarded-Proto headers and by writing into trusted.jfrog/metadata paths via COPY/MOVE/WebDAV, creating a route to software supply-chain compromise; the researcher recommends applying vendor patches, disabling unnecessary anonymous access, reviewing repository permissions, and stripping client-supplied headers at the routing boundary.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
