Jfrog Artifactory prior to 6.17.0 uses default passwords (such as “password”) for administrative accounts and does not require users to change them. This may allow unauthorized network-based attackers to completely compromise of Jfrog Artifactory.
View the template here CVE-2019-17444.yaml
References:
https://nvd.nist.gov/vuln/detail/CVE-2019-17444