.. / CVE-2019-17444

Exploit for Jfrog Artifactory <6.17.0 - Default Admin Password (CVE-2019-17444)

Description:

Jfrog Artifactory prior to 6.17.0 uses default passwords (such as “password”) for administrative accounts and does not require users to change them. This may allow unauthorized network-based attackers to completely compromise of Jfrog Artifactory.

Nuclei Template

View the template here CVE-2019-17444.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2019/CVE-2019-17444.yaml
Copy

References:

https://nvd.nist.gov/vuln/detail/CVE-2019-17444
https://github.com/ARPSyndicate/kenzer-templates
https://www.jfrog.com/confluence/display/JFROG/JFrog+Artifactory
https://www.jfrog.com/confluence/display/JFROG/Artifactory+Release+Notes