CVE-2024-24763
JumpServer Open Redirect Vulnerability
Record summary
CVE-2024-24763 has a selected CVSS score of 4.3 (medium); EIP currently links 1 Nuclei template.
Description
JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to version 3.10.0, attackers can exploit this vulnerability to construct malicious links, leading users to click on them, thereby facilitating phishing attacks or cross-site scripting attacks. Version 3.10.0 contains a patch for this issue. No known workarounds are available.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 22, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
jumpserverBrowse jumpserver / jumpserver | CVE List | < 3.10.0 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMJumpServer < 3.10.0 - Open RedirectCVSS 4.3
JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to version 3.10.0, attackers can exploit this vulnerability to construct malicious links, leading users to click on them, thereby facilitating phishing attacks or cross-site scripting attacks. Version 3.10.0 contains a patch for this issue. No known workarounds are available.
Impact
Unauthenticated attackers can redirect users to malicious URLs via the next parameter, facilitating phishing attacks or cross-site scripting.
Remediation
Update JumpServer to version 3.10.0 or later.
Source: ProjectDiscovery