Skip to main content

Vendor/product archive

fit2cloud / jumpserver CVEs

Beta · best-effort

24 CVEs tagged to fit2cloud / jumpserver6 Critical, 7 High, 10 Medium, 1 Low, 0 Unrated.

CVE-2026-31864

Published Mar 13, 2026

JumpServer is an open source bastion host and an operation and maintenance security audit system. a Server-Side Template Injection (SSTI) vulnerability exists in JumpServer's Appl…

CVSS 6.8 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-31798

Published Mar 13, 2026

JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v4.10.16-lts, JumpServer improperly validates certificates in the Custom…

CVSS 5.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-58044

Published Dec 1, 2025

JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v3.10.19 and v4.10.5, The /core/i18n// endpoint uses the Referer header…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-62795

Published Oct 30, 2025

JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v3.10.21-lts and v4.10.12-lts, a low-privileged authenticated user can i…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-62712

Published Oct 30, 2025

JumpServer is an open source bastion host and an operation and maintenance security audit system. In JumpServer versions prior to v3.10.20-lts and v4.10.11-lts, an authenticated,…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-27095

Published Mar 31, 2025

JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to 4.8.0 and 3.10.18, an attacker with a low-privileged account can access…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-40629

Published Jul 18, 2024

JumpServer is an open-source Privileged Access Management (PAM) tool that provides DevOps and IT teams with on-demand and secure access to SSH, RDP, Kubernetes, Database and Remot…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-40628

Published Jul 18, 2024

JumpServer is an open-source Privileged Access Management (PAM) tool that provides DevOps and IT teams with on-demand and secure access to SSH, RDP, Kubernetes, Database and Remot…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-29202

Published Mar 29, 2024

JumpServer is an open source bastion host and an operation and maintenance security audit system. Attackers can exploit a Jinja2 template injection vulnerability in JumpServer's A…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-29201

Published Mar 29, 2024

JumpServer is an open source bastion host and an operation and maintenance security audit system. Attackers can bypass the input validation mechanism in JumpServer's Ansible to ex…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-29024

Published Mar 29, 2024

JumpServer is an open source bastion host and an operation and maintenance security audit system. An authenticated user can exploit the Insecure Direct Object Reference (IDOR) vul…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-29020

Published Mar 29, 2024

JumpServer is an open source bastion host and an operation and maintenance security audit system. An authorized attacker can obtain sensitive information contained within playbook…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-24763

Published Feb 20, 2024

JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to version 3.10.0, attackers can exploit this vulnerability to construct ma…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-48193

Published Nov 28, 2023

Insecure Permissions vulnerability in JumpServer GPLv3 v.3.8.0 allows a remote attacker to execute arbitrary code via bypassing the command filtering function. NOTE: this is dispu…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-46138

Published Oct 31, 2023

JumpServer is an open source bastion host and maintenance security audit system that complies with 4A specifications. Prior to version 3.8.0, the default email for initial user ad…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-46123

Published Oct 25, 2023

jumpserver is an open source bastion machine, professional operation and maintenance security audit system that complies with 4A specifications. A flaw in the Core API allows atta…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-43651

Published Sep 27, 2023

JumpServer is an open source bastion host. An authenticated user can exploit a vulnerability in MongoDB sessions to execute arbitrary commands, leading to remote code execution. T…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-42818

Published Sep 27, 2023

JumpServer is an open source bastion host. When users enable MFA and use a public key for authentication, the Koko SSH server does not verify the corresponding SSH private key. An…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-43652

Published Sep 27, 2023

JumpServer is an open source bastion host. As an unauthenticated user, it is possible to authenticate to the core API with a username and an SSH public key without needing a passw…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-43650

Published Sep 27, 2023

JumpServer is an open source bastion host. The verification code for resetting user's password is vulnerable to brute-force attacks due to the absence of rate limiting. JumpServer…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-42820

Published Sep 27, 2023

JumpServer is an open source bastion host. This vulnerability is due to exposing the random number seed to the API, potentially allowing the randomly generated verification codes…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2023-42819

Published Sep 27, 2023

JumpServer is an open source bastion host. Logged-in users can access and modify the contents of any file on the system. A user can use the 'Job-Template' menu and create a playbo…

CVSS 8.9 · High
Vendor/product tagsBeta · best-effort

CVE-2023-42442

Published Sep 15, 2023

JumpServer is an open source bastion host and a professional operation and maintenance security audit system. Starting in version 3.0.0 and prior to versions 3.5.5 and 3.6.4, sess…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-28110

Published Mar 16, 2023

Jumpserver is a popular open source bastion host, and Koko is a Jumpserver component that is the Go version of coco, refactoring coco's SSH/SFTP service and Web Terminal service.…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-24 of 24 CVEsPage 1 of 1