CVE-2023-42820
HIGHJumpServer 2.24.0-2.28.18 - Exposure of Sensitive Information via Random Seed in API
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2023-42820. PoCs published by C1ph3rX13, Startr4ck.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2023-42820, targeting a password reset vulnerability in an unspecified web application. The exploit automates CAPTCHA bypass, CSRF token extraction, and password reset token manipulation to achieve unauthorized account access.
Description
JumpServer is an open source bastion host. This vulnerability is due to exposing the random number seed to the API, potentially allowing the randomly generated verification codes to be replayed, which could lead to password resets. If MFA is enabled users are not affect. Users not using local authentication are also not affected. Users are advised to upgrade to either version 2.28.19 or to 3.6.5. There are no known workarounds or this issue.
Exploits (2)
This repository contains a functional exploit for CVE-2023-42820, targeting a password reset vulnerability in an unspecified web application. The exploit automates CAPTCHA bypass, CSRF token extraction, and password reset token manipulation to achieve unauthorized account access.
The repository lacks functional exploit code and instead provides vague descriptions and external image links. It mentions password reset and shell access but does not include technical details or PoC code.
References (2)
Scores
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L