2 ms·
> the agent happened to escape via a 0-day exploit from the package proxy cache to access the internet I have same familiarity with JFrog Artifactory(which the
by maxnevermind 2mo ago
> the agent happened to escape via a 0-day exploit from the package proxy cache to access the internet
I have same familiarity with JFrog Artifactory(which they used in this case) and I'm confused with how you can gain access to the internet through it, even in theory. Isn't JFrog just exposed with a basic REST API for package upload/extraction? I'm not a security expert but how is that possible to get internet access through simple GET/PUT request API?
- wonnage 2mo agoThe package cache proxy is usually used to fetch from the public repository (npm, rubygems, etc.) so I think it could be feasible to craft some package metadata to trick it into GETing unexpected things. PUT/POST could be possible via attempting to publish
- simonw 2mo agoThere are a bunch of hints at that in their most recent release notes - 9 fixed security issues, 8 of which were reported by OpenAI staff members: https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases#artifactory-7161 https://docs.jfrog.com/releases/docs/artifactory-self-manage...
- what 2mo agoPage just crashes on iOS safari. Product is probably slop too.