Two Artifactory token flaws compose into unauthenticated administrative control and server-side code execution.
JFrog Artifactory, a self-hosted artifact repository used in software build and deployment pipelines.
An unauthenticated endpoint discloses an internal anonymous-user JWT, and missing scope validation lets that token mint administrator authority.
Detail and 2 sources
The chain was used to create administrators, execute operating-system commands through a Groovy plugin, and install a persistent Rust backdoor.
JFrog has fixed the token flaws, but the remediation does not establish complete revocation of access or persistence created before upgrade.