Jumpserver

Jumpserver

10 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.5%
  • Veröffentlicht 17.08.2026 21:16:45
  • Zuletzt bearbeitet 18.08.2026 19:16:48

JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to 4.10.17, an authenticated administrator with Applet Host management and deployment permissions can inject Jinja2 expressions into the IP/Host f...

  • EPSS 0.33%
  • Veröffentlicht 17.08.2026 21:16:45
  • Zuletzt bearbeitet 18.08.2026 14:17:07

JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to 4.10.17, a user with the users.invite_user permission can submit an existing member to POST /api/v1/users/users/invite/, causing the organizati...

  • EPSS 0.27%
  • Veröffentlicht 17.08.2026 21:01:48
  • Zuletzt bearbeitet 18.08.2026 14:17:11

JumpServer is an open source bastion host and an operation and maintenance security audit system. From 4.8.0 until 4.10.17, an authenticated user with SFTP permission to an authorized asset can submit crafted traversal paths through the KoKo Web Term...

  • EPSS 0.35%
  • Veröffentlicht 13.03.2026 19:22:05
  • Zuletzt bearbeitet 18.03.2026 13:09:28

JumpServer is an open source bastion host and an operation and maintenance security audit system. a Server-Side Template Injection (SSTI) vulnerability exists in JumpServer's Applet and VirtualApp upload functionality. This vulnerability can only be ...

  • EPSS 0.1%
  • Veröffentlicht 13.03.2026 19:15:26
  • Zuletzt bearbeitet 18.03.2026 13:07:58

JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v4.10.16-lts, JumpServer improperly validates certificates in the Custom SMS API Client. When JumpServer sends MFA/OTP codes via Custom SMS API...

  • EPSS 0.5%
  • Veröffentlicht 01.12.2025 20:17:44
  • Zuletzt bearbeitet 05.12.2025 19:48:05

JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v3.10.19 and v4.10.5, The /core/i18n// endpoint uses the Referer header as the redirection target without proper validation, which could lead t...

Exploit
  • EPSS 0.27%
  • Veröffentlicht 30.10.2025 16:56:09
  • Zuletzt bearbeitet 12.11.2025 15:26:50

JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v3.10.21-lts and v4.10.12-lts, a low-privileged authenticated user can invoke LDAP configuration tests and start LDAP synchronization by sendin...

  • EPSS 0.47%
  • Veröffentlicht 30.10.2025 16:15:36
  • Zuletzt bearbeitet 12.11.2025 15:26:13

JumpServer is an open source bastion host and an operation and maintenance security audit system. In JumpServer versions prior to v3.10.20-lts and v4.10.11-lts, an authenticated, non-privileged user can retrieve connection tokens belonging to other u...

Exploit
  • EPSS 0.31%
  • Veröffentlicht 31.03.2025 16:15:23
  • Zuletzt bearbeitet 12.11.2025 15:50:12

JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to 4.8.0 and 3.10.18, an attacker with a low-privileged account can access the Kubernetes session feature and manipulate the kubeconfig file to re...

  • EPSS 2.75%
  • Veröffentlicht 23.07.2021 21:15:07
  • Zuletzt bearbeitet 21.11.2024 06:21:03

An issue in Jumpserver before 2.6.2, before 2.5.4, before 2.4.5 allows attackers to create a connection token through an API which does not have access control and use it to access sensitive assets.