Tag: package manipulation
1 article

JFrog Artifactory Flaws Expose Software Supply Chain to Manipulation
Critical flaws in JFrog Artifactory have been uncovered, putting software supply chains at risk of manipulation by allowing low-privileged users to alter package metadata. These vulnerabilities, already patched by JFrog, highlight the importance of securing metadata generation and trusted internal paths to prevent potential software supply chain compromises.