Vulnerability record · CVE-2019-9733 · published 11 April 2019
CVE-2019-9733: JFrog Artifactory access-admin IP whitelist bypass via X-Forwarded-For
Jfrog · Artifactory
Artifactory 6.7.3 restricts the access-admin password-reset account to connections from localhost, but the whitelist check trusts the X-Forwarded-For header. An unauthenticated attacker can spoof that header, log in with the default access-admin credentials, and use the API to mint authentication tokens for any user, including admin.
Description
An issue was discovered in JFrog Artifactory 6.7.3. By default, the access-admin account is used to reset the password of the admin account in case an administrator gets locked out from the Artifactory console. This is only allowable from a connection directly from localhost, but providing a X-Forwarded-For HTTP header to the request allows an unauthenticated user to login with the default credentials of the access-admin account while bypassing the whitelist of allowed IP addresses. The access-admin account can use Artifactory's API to request authentication tokens for all users including the admin account and, in turn, assume full control of all artifacts and repositories managed by Artifactory.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable authentication bypass with public exploit code and a CVSS of 9.8 that yields full control of the artifact repository.
What it is
Artifactory 6.7.3 restricts the access-admin password-reset account to connections from localhost, but the whitelist check trusts the X-Forwarded-For header. An unauthenticated attacker can spoof that header, log in with the default access-admin credentials, and use the API to mint authentication tokens for any user, including admin.
Impact
The attacker gains full control of all artifacts and repositories managed by Artifactory, including the ability to impersonate the admin account.
Attack surface
Reachable over the network via HTTP requests to the Artifactory console; no authentication or user interaction is required, only the ability to send a crafted X-Forwarded-For header.
Exploitation
Not listed in CISA KEV, but public exploit references exist (Packet Storm, CipherTechs) and EPSS is 0.52948 (98.9th percentile), indicating high likelihood of exploitation.
What to do
- Upgrade Artifactory to 6.8.6 or later, which addresses this issue per the vendor release notes.
- Change the default access-admin credentials and disable or restrict the access-admin account if not needed.
- Do not trust client-supplied X-Forwarded-For headers; configure the reverse proxy to strip or overwrite them and only accept connections from known proxies.
- Restrict network access to the Artifactory console and API to trusted management networks.
- Rotate all Artifactory user and admin tokens after patching in case of prior compromise.
Detection
- Search Artifactory access logs for requests to the access-admin or password-reset endpoints containing an X-Forwarded-For header.
- Alert on successful logins to the access-admin account, especially from non-localhost source addresses.
- Monitor for API calls that generate authentication tokens for multiple or privileged users in a short window.
- Review audit logs for unexpected token creation or repository permission changes tied to access-admin.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/152172/JFrog-Artifactory-Administrator-Authentication-Bypass.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.ciphertechs.com/jfrog-artifactory-advisory/ | ExploitThird Party Advisory |
| https://www.jfrog.com/confluence/display/RTF/Release+Notes#ReleaseNotes-Artifactory6.8.6 | Release NotesVendor Advisory |
| http://packetstormsecurity.com/files/152172/JFrog-Artifactory-Administrator-Authentication-Bypass.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.ciphertechs.com/jfrog-artifactory-advisory/ | ExploitThird Party Advisory |
| https://www.jfrog.com/confluence/display/RTF/Release+Notes#ReleaseNotes-Artifactory6.8.6 | Release NotesVendor Advisory |
Track CVE-2019-9733 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-9733), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.