← Zuruck zu CVEs
CVE-2023-48193
CRITICAL9.8
Beschreibung
Insecure Permissions vulnerability in JumpServer GPLv3 v.3.8.0 allows a remote attacker to execute arbitrary code via bypassing the command filtering function. NOTE: this is disputed because command filtering is not intended to restrict what code can be run by authorized users who are allowed to execute files.
CVE Details
CVSS v3.1 Bewertung9.8
SchweregradCRITICAL
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht11/28/2023
Zuletzt geandert11/21/2024
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
fit2cloud:jumpserver
Referenzen
http://jumpserver.com(cve@mitre.org)
https://github.com/jumpserver/jumpserver(cve@mitre.org)
https://github.com/jumpserver/jumpserver/issues/13394(cve@mitre.org)
http://jumpserver.com(af854a3a-2127-422b-91ae-364da2661108)
https://blog.fit2cloud.com/?p=8cf83cd9-c23b-4625-9350-38926fb7f88e(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/296430468/lcc_test/blob/main/jumpserver_BUG.md(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/jumpserver/jumpserver(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/jumpserver/jumpserver/issues/13394(af854a3a-2127-422b-91ae-364da2661108)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.