Cyber Resilience

CVE-2019-9733

Jfrog Artifactory 6.7.3

Public PoCHigh EPSS
Published
11 April 2019
Modified
21 November 2024
Patch / advisory
CVSS Score v3 9.8
Click a component to see what it means
Raw vectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.54 99th percentile
Risk Priority 97 floored blend · peak EPSS

Summary

CVE-2019-9733 is a critical-severity an unspecified weakness vulnerability in Jfrog Artifactory. Its CVSS base score is 9.8 (Critical).

Operationally, ranked in the top 1% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.

EU & UK References

Vulnerability Data

An issue was discovered in JFrog Artifactory 6.7.3. By default, the access-admin account is used to reset the password of the admin account in case an administrator gets locked out from the Artifactory console. This is only allowable from a…

more

connection directly from localhost, but providing a X-Forwarded-For HTTP header to the request allows an unauthenticated user to login with the default credentials of the access-admin account while bypassing the whitelist of allowed IP addresses. The access-admin account can use Artifactory's API to request authentication tokens for all users including the admin account and, in turn, assume full control of all artifacts and repositories managed by Artifactory.

CWE(s)

Related Threats

Likely ATT&CK TechniquesAI

Techniques this vulnerability likely enables, inferred from its description, weakness type, and attributed-actor tradecraft. Confidence is per-technique.

T1190 Exploit Public-Facing Application Initial Accessconfidence: HIGH
Unauthenticated remote exploitation of the Artifactory web application via a crafted X-Forwarded-For header bypasses IP restrictions.
T1078.001 Default Accounts Stealthconfidence: HIGH
Exploitation grants access to the default access-admin account, enabling use of valid default credentials.
T1550.001 Application Access Token Lateral Movementconfidence: HIGH
The access-admin account is used to obtain authentication tokens for other accounts including admin.
T1078.003 Local Accounts Stealthconfidence: MEDIUM
Compromised tokens allow impersonation of any user account within Artifactory.
inferred from description · MITRE ATT&CK Enterprise v19.0

CVEs Like This One

CVE-2023-42661Same product: Jfrog Artifactory
CVE-2023-42509Same product: Jfrog Artifactory
CVE-2023-42662Same product: Jfrog Artifactory
CVE-2024-2247Same product: Jfrog Artifactory
CVE-2024-3505Same product: Jfrog Artifactory
CVE-2019-17444Same product: Jfrog Artifactory
CVE-2023-42508Same product: Jfrog Artifactory

Affected Assets

jfrog
artifactory
6.7.3

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References