CVE-2019-17444

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
12/10/2020
Last modified:
20/10/2020

Description

Jfrog Artifactory uses default passwords (such as "password") for administrative accounts and does not require users to change them. This may allow unauthorized network-based attackers to completely compromise of Jfrog Artifactory. This issue affects Jfrog Artifactory versions prior to 6.17.0.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:* 6.17.0 (excluding)