CVE-2019-17444: JFrog Artifactory does not enforce default admin password change
Published Oct 12, 2020
·Updated
Jfrog Artifactory uses default passwords (such as "password") for administrative accounts and does not require users to change them. This may allow unauthorized network-based attackers to completely compromise of Jfrog Artifactory. This issue affects Jfrog Artifactory versions prior to 6.17.0.
Affected Software
1 affected component
JFrog Artifactory<6.17.0
Remediation
Information
This is fixed in 6.17, and 7.x and later releases.
Event History
Oct 12, 2020
CVE Published
via MITRE·09:55 PM
Data Sourced
via MITRE·09:55 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-17444.
2
What is the severity of CVE-2019-17444?
CVE-2019-17444 has a severity level of critical.
3
How does the vulnerability in Jfrog Artifactory occur?
The vulnerability in Jfrog Artifactory occurs due to the use of default passwords for administrative accounts and the lack of a requirement for users to change them.
4
Which versions of Jfrog Artifactory are affected by this vulnerability?
Jfrog Artifactory versions prior to 6.17.0 are affected by this vulnerability.
5
How can I fix CVE-2019-17444?
To fix CVE-2019-17444, you should upgrade Jfrog Artifactory to version 6.17.0 or higher.