github.com
https://github.com/jumpserver/jumpserver/commit/42337f0d00b2a8d45ef063eb5b7deeef81597da5 CVE-2023-42820
HIGH
Random seed leakage in Jumpserver
Record summary
CVE-2023-42820 has a selected CVSS score of 7.0 (high); EIP currently links 3 repository PoCs.
Description
JumpServer is an open source bastion host. This vulnerability is due to exposing the random number seed to the API, potentially allowing the randomly generated verification codes to be replayed, which could lead to password resets. If MFA is enabled users are not affect. Users not using local authentication are also not affected. Users are advised to upgrade to either version 2.28.19 or to 3.6.5. There are no known workarounds or this issue.
Description source: CVE List
Exploitation context
Available material
- Repository PoCs
- 3
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 23, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
jumpserverBrowse jumpserver / jumpserver | CVE List | >= 2.24, < 2.28.19 | affected |
| >= 3.0.0, < 3.6.5 | affected |
Proofs of concept
3Repository PoCs
GitHubC1ph3rX13/CVE-2023-42820Repository PoCby C1ph3rX13Stars: 56Not analyzed7 files
GitHubStartr4ck/cve-2023-42820Repository PoCby Startr4ckStars: 2Not analyzed3 files
GitHubtarihub/blackjumpRepository PoCby tarihubStars: 276Not analyzed9 files
References
2github.comConfirmation
https://github.com/jumpserver/jumpserver/security/advisories/GHSA-7prv-g565-82qp