| ▲ | lovasoa 5 hours ago | ||||||||||||||||||||||||||||||||||||||||||||||
What they conveniently omit in the blog post is what the vulnerability was: it seems like they renewed JWTs without checking the signature at all ! You could write arbitrary info in an old token, and get it signed without any verification. | |||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | simonw 4 hours ago | parent | next [-] | ||||||||||||||||||||||||||||||||||||||||||||||
That video suggests that RTDEV-92030 was the fix for the issue - but https://docs.jfrog.com/releases/docs/artifactory-self-manage... says that issue was resolved in a 15 July 2026 release of Artifactory, which doesn't fit our timeline - that was prior to the original Hugging Face post on 16 July which was several days before OpenAI had confessed. | |||||||||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | patmorgan23 4 hours ago | parent | prev [-] | ||||||||||||||||||||||||||||||||||||||||||||||
I believe the technical term for that is "big oof" | |||||||||||||||||||||||||||||||||||||||||||||||