CVE-2019-9733: JFrog Artifactory 6.7.3 – Admin Login Bypass

CVE-2019-9733: JFrog Artifactory 6.7.3 - Admin Login Bypass-渗透云记 - 专注于网络安全与技术分享
CVE-2019-9733: JFrog Artifactory 6.7.3 – Admin Login Bypass
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2019-9733: JFrog Artifactory 6.7.3 – Admin Login Bypass

漏洞描述

JFrog Artifactory 6.7.3 is vulnerable to an admin login bypass issue because by default the access-admin account is used to reset the password of the admin account. While this is only allowable from a connection directly from localhost, providing an X-Forwarded-For HTTP header to the request allows an unauthenticated user to login with the default credentials of the access-admin account while bypassing the whitelist of allowed IP addresses. The access-admin account can use Artifactory's API to request authentication tokens for all users including the admin account and, in turn, assume full control of all artifacts and repositories managed by Artifactory.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享