Breaking Corporate Maven Repositories - Exploiting Vulnerabilities in Repository Managers
Ekoparty Security Conference via YouTube
PowerBI Data Analyst - Create visualizations and dashboards from scratch
Live Online Classes in Design, Coding & AI — Small Classes, Free Retakes
Overview
Google, IBM & Meta Certificates — All 10,000+ Courses at 40% Off
One annual plan covers every course and certificate on Coursera. 40% off for a limited time.
Get Full Access
Watch a 31-minute conference talk from Ekoparty Security Conference where security researcher Michael Stepankin explores vulnerabilities in corporate Maven repository managers. Discover how in-house repository managers like Sonatype Nexus and JFrog Artifactory, commonly used in Java ecosystems for artifact storage and dependency caching, can be exploited through specially crafted artifacts. Learn about recently discovered CVEs and see demonstrations of exploits that can achieve pre-auth remote code execution and local artifact poisoning. Gain valuable insights into web security, Java security, and supply chain vulnerabilities that are particularly relevant for security professionals working with enterprise Java environments and artifact management systems.
Syllabus
Breaking corporate Maven repositories - Michael Stepankin - Ekoparty 2024
Taught by
Ekoparty Security Conference