CVE-2019-17444
Last modified
CVE-2019-17444 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Jfrog Artifactory uses default passwords (such as "password") for administrative accounts and does not require users to change them. This may allow unauthorized network-based attackers to completely compromise of Jfrog Artifactory. EPSS estimates a 69.45% chance of exploitation in the next 30 days.
Description
Jfrog Artifactory uses default passwords (such as "password") for administrative accounts and does not require users to change them. This may allow unauthorized network-based attackers to completely compromise of Jfrog Artifactory. This issue affects Jfrog Artifactory versions prior to 6.17.0.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Jfrog | Artifactory | < 6.17.0 |
References
- https://www.jfrog.com/confluence/display/JFROG/Artifactory+Release+NotesRelease Notes, Vendor Advisory
- https://www.jfrog.com/confluence/display/JFROG/Artifactory+Release+NotesRelease Notes, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-17444?
How severe is CVE-2019-17444?
How do I fix CVE-2019-17444?
Are you affected by CVE-2019-17444?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
