Описание
Insecure Permissions vulnerability in JumpServer GPLv3 v.3.8.0 allows a remote attacker to execute arbitrary code via bypassing the command filtering function. NOTE: this is disputed because command filtering is not intended to restrict what code can be run by authorized users who are allowed to execute files.
Ссылки
- Product
- ExploitThird Party Advisory
- Product
- Product
- ExploitThird Party Advisory
- Product
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:fit2cloud:jumpserver:3.8.0:*:*:*:*:*:*:*
EPSS
Процентиль: 88%
0.03849
Низкий
9.8 Critical
CVSS3
Дефекты
NVD-CWE-noinfo
Связанные уязвимости
CVSS3: 9.8
github
около 2 лет назад
Insecure Permissions vulnerability in JumpServer GPLv3 v.3.8.0 allows a remote attacker to execute arbitrary code via bypassing the command filtering function.
EPSS
Процентиль: 88%
0.03849
Низкий
9.8 Critical
CVSS3
Дефекты
NVD-CWE-noinfo