Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h699-2469-3vhg

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

An issue in Jumpserver 2.6.2 and below allows attackers to create a connection token through an API which does not have access control and use it to access sensitive assets.

An issue in Jumpserver 2.6.2 and below allows attackers to create a connection token through an API which does not have access control and use it to access sensitive assets.

EPSS

Процентиль: 77%
0.01077
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 9.8
nvd
больше 4 лет назад

An issue in Jumpserver before 2.6.2, before 2.5.4, before 2.4.5 allows attackers to create a connection token through an API which does not have access control and use it to access sensitive assets.

EPSS

Процентиль: 77%
0.01077
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-74