SECURITY·중요도 9·2026. 09. 28.·InfoQ

Artifactory Vulnerabilities Under Active Exploitation Enable Authentication Bypass and Admin Access

── KO ──────────────────

Artifactory의 취약점으로 인해 인증 우회 및 관리자 접근이 가능해졌습니다.

Artifactory에서 발견된 세 가지 취약점이 활성화된 공격에 이용되고 있으며, 이는 인터넷에 연결된 자가 호스팅 배포에서 인증 우회를 가능하게 합니다. 공격자는 이 취약점을 통해 5분 이내에 영구 관리자 접근을 획득할 수 있으며, 이후 자격 증명 및 키 도난, 임의 코드 실행, 지속성 및 반 포렌식 조치를 포함한 위험한 활동을 수행할 수 있습니다.


── EN ──────────────────

Artifactory vulnerabilities allow authentication bypass and admin access under active exploitation.

Three vulnerabilities in Artifactory are currently under active exploitation, enabling authentication bypass on self-hosted deployments accessible via the internet. Attackers can gain persistent admin access in under five minutes, allowing for dangerous activities such as credential and key theft, arbitrary code execution, persistence, and anti-forensics measures.

원문 보기 →목록으로