Vulnerability record · CVE-2019-17444 · published 12 October 2020
CVE-2019-17444: JFrog Artifactory default admin passwords allow full compromise
Jfrog · Artifactory
JFrog Artifactory ships with default passwords such as "password" for administrative accounts and does not force a change. Because these credentials are well known and unchanged, an attacker who can reach the service can log in as an administrator. The flaw affects Artifactory versions prior to 6.17.0.
Description
Jfrog Artifactory uses default passwords (such as "password") for administrative accounts and does not require users to change them. This may allow unauthorized network-based attackers to completely compromise of Jfrog Artifactory. This issue affects Jfrog Artifactory versions prior to 6.17.0.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or interaction required and very high EPSS, allowing complete compromise of the repository.
What it is
JFrog Artifactory ships with default passwords such as "password" for administrative accounts and does not force a change. Because these credentials are well known and unchanged, an attacker who can reach the service can log in as an administrator. The flaw affects Artifactory versions prior to 6.17.0.
Impact
An unauthenticated network attacker gains full administrative control of the Artifactory instance, including read and write access to all hosted artifacts and configuration. This can lead to supply chain compromise of software distributed through the repository.
Attack surface
The vulnerability is reachable over the network via the Artifactory web interface or API, with no authentication and no user interaction required, as reflected in the CVSS vector AV:N/AC:L/PR:N/UI:N. Any instance exposed to an untrusted network and left with default credentials is directly at risk.
Exploitation
The record shows no CISA KEV listing and no ransomware association, but EPSS is very high at 0.694 (99.3rd percentile), indicating strong likelihood of exploitation activity. References are vendor advisories and release notes only, with no public exploit tag.
What to do
- Upgrade Artifactory to version 6.17.0 or later, which is the fixed release per the vendor.
- Immediately change all default administrative passwords and enforce a strong password policy.
- Restrict network access to the Artifactory UI and API using firewalls or allowlists so it is not internet-exposed.
- Audit all accounts for default or weak credentials and disable unused administrative accounts.
- Enable authentication logging and alerting on administrative logins from unexpected sources.
Detection
- Search authentication logs for successful logins using known default credentials such as "admin"/"password".
- Monitor for administrative logins from new or external IP addresses, especially outside normal hours.
- Alert on creation of new admin users, API keys or tokens, and on bulk artifact downloads or uploads.
- Review Artifactory configuration and user listings for accounts still using default or weak passwords.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.jfrog.com/confluence/display/JFROG/Artifactory+Release+Notes | Release NotesVendor Advisory |
| https://www.jfrog.com/confluence/display/JFROG/JFrog+Artifactory | Vendor Advisory |
| https://www.jfrog.com/confluence/display/JFROG/Artifactory+Release+Notes | Release NotesVendor Advisory |
| https://www.jfrog.com/confluence/display/JFROG/JFrog+Artifactory | Vendor Advisory |
Track CVE-2019-17444 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-17444), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.