Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-46123

Опубликовано: 25 окт. 2023
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

jumpserver is an open source bastion machine, professional operation and maintenance security audit system that complies with 4A specifications. A flaw in the Core API allows attackers to bypass password brute-force protections by spoofing arbitrary IP addresses. By exploiting this vulnerability, attackers can effectively make unlimited password attempts by altering their apparent IP address for each request. This vulnerability has been patched in version 3.8.0.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:fit2cloud:jumpserver:*:*:*:*:*:*:*:*
Версия до 3.8.0 (исключая)

EPSS

Процентиль: 63%
0.00444
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-307
CWE-307

EPSS

Процентиль: 63%
0.00444
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-307
CWE-307