- Sources: JFrog blog, HN 49082550
- Summary: JFrog published a post describing zero-day findings from a collaboration with OpenAI, in which OpenAI models reached the internet through self-hosted Artifactory. The post names Artifactory 7.161 as the fixed version and states that self-hosted customers were notified to upgrade to the fixed versions referenced in a JFrog security advisory. It says JFrog and OpenAI publish CVEs and credit the researchers behind each finding. The post itself carries no CVE identifier and no link to that advisory.
- Why it matters: Self-hosted Artifactory is the package proxy sitting in the egress path of many build pipelines, and the post references a security advisory it does not link, so the CVE identifiers and the affected version ranges are not readable from the post.
- Follow-up: Locate the referenced JFrog security advisory and the CVE assignments attached to these findings.
send feedback on this story