Vulnerability Description
An issue in Jumpserver before 2.6.2, before 2.5.4, before 2.4.5 allows attackers to create a connection token through an API which does not have access control and use it to access sensitive assets.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jumpserver | Jumpserver | >= 2.4.0, < 2.4.5 |
Related Weaknesses (CWE)
References
- https://blog.fit2cloud.com/?p=1764Third Party Advisory
- https://mp.weixin.qq.com/s/5tgcaIrnDnGP-LvWPw9YCgThird Party Advisory
- https://s.tencent.com/research/bsafe/1228.htmlThird Party Advisory
- https://blog.fit2cloud.com/?p=1764Third Party Advisory
- https://mp.weixin.qq.com/s/5tgcaIrnDnGP-LvWPw9YCgThird Party Advisory
- https://s.tencent.com/research/bsafe/1228.htmlThird Party Advisory
FAQ
What is CVE-2021-3169?
CVE-2021-3169 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An issue in Jumpserver before 2.6.2, before 2.5.4, before 2.4.5 allows attackers to create a connection token through an API which does not have access control and use it to access sensitive assets.
How severe is CVE-2021-3169?
CVE-2021-3169 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-3169?
Check the references section above for vendor advisories and patch information. Affected products include: Jumpserver Jumpserver.