Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-17444

Опубликовано: 12 окт. 2020
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Критический

Описание

Jfrog Artifactory uses default passwords (such as "password") for administrative accounts and does not require users to change them. This may allow unauthorized network-based attackers to completely compromise of Jfrog Artifactory. This issue affects Jfrog Artifactory versions prior to 6.17.0.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*
Версия до 6.17.0 (исключая)

EPSS

Процентиль: 100%
0.92493
Критический

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-521
CWE-521

Связанные уязвимости

github
больше 3 лет назад

Jfrog Artifactory uses default passwords (such as "password") for administrative accounts and does not require users to change them. This may allow unauthorized network-based attackers to completely compromise of Jfrog Artifactory. This issue affects Jfrog Artifactory versions prior to 6.17.0.

EPSS

Процентиль: 100%
0.92493
Критический

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-521
CWE-521