CVE-2023-42818

MEDIUM

JumpServer < 3.5.6 - Improper Authentication via SSH Public Key Bypass

Title source: llm
STIX 2.1

Description

JumpServer is an open source bastion host. When users enable MFA and use a public key for authentication, the Koko SSH server does not verify the corresponding SSH private key. An attacker could exploit a vulnerability by utilizing a disclosed public key to attempt brute-force authentication against the SSH service This issue has been patched in versions 3.6.5 and 3.5.6. Users are advised to upgrade. There are no known workarounds for this issue.

References (2)

Core 2

Scores

CVSS v3 5.4
EPSS 0.0058
EPSS Percentile 43.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-287 CWE-307
Status published
Products (1)
fit2cloud/jumpserver < 3.5.6
Published Sep 27, 2023
Tracked Since Feb 18, 2026