CVE-2024-6915 (CVSS 9.3): JFrog Artifactory Flaw Exposes Software Supply Chains to Cache Poisoning - #CVE-2024-6915
JFrog has released a critical security advisory for its Artifactory platform due to a vulnerability identified as CVE-2024-6915, with a CVSS score of 9.3, affecting multiple versions and enabling cache poisoning attacks on software supply chains. Cache poisoning involves manipulating cached software artifacts, potentially leading to data breaches or system takeovers. Users of self-hosted Artifactory are advised to apply security patches immediately, while cloud instances have been updated. Temporary mitigation measures are also provided for those unable to upgrade right away.