logoalt Hacker News

lovasoatoday at 1:49 PM2 repliesview on HN

What they conveniently omit in the blog post is what the vulnerability was: it seems like they renewed JWTs without checking the signature at all ! You could write arbitrary info in an old token, and get it signed without any verification.

https://www.youtube.com/watch?v=q2KCrmQz9WE


Replies

simonwtoday at 3:01 PM

That video suggests that RTDEV-92030 was the fix for the issue - but https://docs.jfrog.com/releases/docs/artifactory-self-manage... says that issue was resolved in a 15 July 2026 release of Artifactory, which doesn't fit our timeline - that was prior to the original Hugging Face post on 16 July which was several days before OpenAI had confessed.

show 3 replies
patmorgan23today at 2:44 PM

I believe the technical term for that is "big oof"