Vulnerability threat dossier

CVE-2019-9733

jfrogartifactory

An issue was discovered in JFrog Artifactory 6.7.3. By default, the access-admin account is used to reset the password of the admin account in case an administrator gets locked out from the Artifactory console. This is only allowable from a connection directly from localhost, but providing a X-Forwarded-For HTTP header to the request allows an unauthenticated user to login with the default credentials of the access-admin account while bypassing the whitelist of allowed IP addresses. The access-admin account can use Artifactory's API to request authentication tokens for all users including the admin account and, in turn, assume full control of all artifacts and repositories managed by Artifactory.

VTP deterministic threat10.6of 100 · CVSS excluded

VTP analyst assessment

Artifactory authentication bypass can expose administrative access

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence83%
Public exploitation · VTP factUNKNOWN

Assessment

JFrog Artifactory 6.7.3 accepts a spoofed X-Forwarded-For header to bypass localhost-only password recovery. An unauthenticated attacker can then log in with default recovery credentials.

Why it matters

  • Artifactory stores and serves software artifacts, making administrative access highly valuable.
  • The stated HTTP-header mechanism is relevant where the vulnerable console is reachable.

Evidence

1 record references and 1 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.

Uncertainties

No public exploitation reporting or remediation detail is included.

First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.

Next watchpoint

If you use Artifactory 6.7.3, apply vendor remediation and restrict console access.

AI baseline history (5)
  1. BASELINE ASSESSED
    Artifactory authentication bypass can expose administrative accessgpt-5.6-terra · low
  2. BASELINE ASSESSED
    JFrog Artifactory authentication bypassgpt-5.6-terra · low
  3. BASELINE ASSESSED
    Critical Artifactory authentication bypassgpt-5.6-terra · low
  4. BASELINE ASSESSED
    JFrog Artifactory localhost trust bypassgpt-5.6-sol · high
  5. BASELINE ASSESSED
    Large EPSS increase; exploitation unverifiedgpt-5.6-sol · high
Technical severityCRITICALCVSS 9.8 · technical context
Public exploitationUNKNOWNGlobal public evidence
Exploit maturityNONE KNOWNReliability not implied
EPSS0.5399th percentile · prediction
Evidence confidence0%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
LOW

The request shares exploitation-associated characteristics with CVE-2019-9733, but the evidence does not identify one CVE with sufficient confidence.

CANDIDATE LEADTechnical consistency 40/100

Basis: deterministic technical candidate

Potentially consistent; exploitation not confirmedDisclosure embargo completed
LOW

The request shares exploitation-associated characteristics with CVE-2019-9733, but the evidence does not identify one CVE with sufficient confidence.

CANDIDATE LEADTechnical consistency 40/100

Basis: deterministic technical candidate

Potentially consistent; exploitation not confirmedDisclosure embargo completed
01

VTP deterministic assessment

Why this matters

  1. 01

    EPSS is 0.53; this is predictive context, not exploitation evidence.

  2. 02

    First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.

02

Material change ledger

What changed

EPSS MATERIAL INCREASEEPSS changed materially from 0.17 to 0.53
EPSS MATERIAL DECREASEEPSS changed materially from 0.53 to 0.17
EPSS MATERIAL INCREASEEPSS changed materially from 0.17 to 0.53
EPSS MATERIAL DECREASEEPSS changed materially from 0.53 to 0.17
EPSS MATERIAL INCREASEEPSS changed materially from 0.17 to 0.53
EPSS MATERIAL DECREASEEPSS changed materially from 0.53 to 0.17
EPSS MATERIAL INCREASEEPSS changed materially from 0.17 to 0.53
03

Claim provenance

Evidence and source independence

0publications detected
0underlying evidence chains

0 primary sources · 0 dependent secondary reports · 0 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

04

Event history

Threat timeline

  1. 18:3624 Sept
    EPSS MATERIAL INCREASE

    EPSS changed materially from 0.17 to 0.53

    Predictive context changed; this is not exploitation evidence.

  2. 13:4421 Sept
    EPSS MATERIAL DECREASE

    EPSS changed materially from 0.53 to 0.17

    Predictive context changed; this is not exploitation evidence.

  3. 11:0807 Sept
    EPSS MATERIAL INCREASE

    EPSS changed materially from 0.17 to 0.53

    Predictive context changed; this is not exploitation evidence.

  4. 12:0506 Sept
    EPSS MATERIAL DECREASE

    EPSS changed materially from 0.53 to 0.17

    Predictive context changed; this is not exploitation evidence.

  5. 18:4630 Aug
    EPSS MATERIAL INCREASE

    EPSS changed materially from 0.17 to 0.53

    Predictive context changed; this is not exploitation evidence.

  6. 20:4128 Aug
    EPSS MATERIAL DECREASE

    EPSS changed materially from 0.53 to 0.17

    Predictive context changed; this is not exploitation evidence.

  7. 00:3425 Aug
    EPSS MATERIAL INCREASE

    EPSS changed materially from 0.17 to 0.53

    Predictive context changed; this is not exploitation evidence.

  8. 01:3124 Aug
    EPSS MATERIAL DECREASE

    EPSS changed materially from 0.53 to 0.17

    Predictive context changed; this is not exploitation evidence.

05

Original publications

Source record

06

Technical vulnerability data

Context, not threat proof

VTP threat score10.6vtp-threat-v1-public
Public exploitation0 / 30
EPSS prediction10.59 / 20
Exploit availability0 / 15
Source independence0 / 15
Intelligence recency0 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
9.8 · CRITICAL
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
Unknown
CPE records
1
Deterministic history records
20
Primary technical reference
07

Raw observations

First-party sensor records

First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.