S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2019-9733 Scanner

Detects 'Authentication Bypass' vulnerability in JFrog Artifactory affects v. 6.7.3.

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.5k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2019-9733
9.8
CVSS

An issue was discovered in JFrog Artifactory 6.7.3. By default, the access-admin account is used to reset the password of the admin account in case an administrator gets locked out from the Artifactory console. This is only allowable from a connection directly from localhost, but providing a X-Forwarded-For HTTP header to the request allows an unauthenticated user to login with the default credentials of the access-admin account while bypassing the whitelist of allowed IP addresses. The access-admin account can use Artifactory's API to request authentication tokens for all users including the admin account and, in turn, assume full control of all artifacts and repositories managed by Artifactory.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

JFrog Artifactory is a popular tool used for managing software packages, releases, and binaries. It acts as a central hub for housing all software artifacts in one single place. Developers use Artifactory to store, manage and share software components within an organization. Artifactory is a crucial tool for organizations that rely on DevOps practices and rely heavily on automation and continuous delivery.

In early 2019, a vulnerability in the Artifactory tool, labeled CVE-2019-9733, was discovered by security researchers. This vulnerability allowed unauthenticated users to bypass the whitelist of allowed IP addresses and gain access to the default access-admin account to reset passwords. The issue with the vulnerability was that anyone could log in to the system easily and could use the system’s API to authenticate tokens for all users, including the admin accounts, making it easy for attackers to gain control of repositories and artifacts.

The exploitation of the vulnerability allows an attacker to gain control of the Artifactory system and all the software packages that it stores. It enables an attacker to access confidential data stored in the tool, including customer data, login credentials, and other sensitive information that could lead to severe consequences.

By using the pro features of the s4e.io platform, users can easily and quickly learn about vulnerabilities in their digital assets. The platform provides detailed information about vulnerabilities and advises on how to remediate them promptly. s4e.io provides vulnerability management solutions that enable organizations to strengthen their security posture, address issues early, and protect their critical assets from potential attack vectors.

 

REFERENCES

Solution Advice

To protect against the CVE-2019-9733 vulnerability, JFrog released a fix, which was included in Artifactory version 6.8.6 or later versions. In addition, users can take the following precautions to ensure their systems are secured:

  • Always keep the Artifactory software up to date with the latest version available
  • Implement IP filtering rules to block all access from foreign origin IP addresses
  • Restrict access to Artifactory to authenticated users only and limit the number of users with admin privileges
  • Enable two-factor authentication for all users

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2019-9733 scanner - Authentication Bypass vulnerability in JFrog Artifactory | S4E