← Back to CVEs
CVE-2023-48193
CRITICAL9.8
Description
Insecure Permissions vulnerability in JumpServer GPLv3 v.3.8.0 allows a remote attacker to execute arbitrary code via bypassing the command filtering function. NOTE: this is disputed because command filtering is not intended to restrict what code can be run by authorized users who are allowed to execute files.
CVE Details
CVSS v3.1 Score9.8
SeverityCRITICAL
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
Published11/28/2023
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0
Affected Products
fit2cloud:jumpserver
References
http://jumpserver.com(cve@mitre.org)
https://github.com/jumpserver/jumpserver(cve@mitre.org)
https://github.com/jumpserver/jumpserver/issues/13394(cve@mitre.org)
http://jumpserver.com(af854a3a-2127-422b-91ae-364da2661108)
https://blog.fit2cloud.com/?p=8cf83cd9-c23b-4625-9350-38926fb7f88e(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/296430468/lcc_test/blob/main/jumpserver_BUG.md(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/jumpserver/jumpserver(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/jumpserver/jumpserver/issues/13394(af854a3a-2127-422b-91ae-364da2661108)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.