CVE-2023-43652
Last modified
CVE-2023-43652 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. JumpServer is an open source bastion host. As an unauthenticated user, it is possible to authenticate to the core API with a username and an SSH public key without needing a password or the corresponding SSH private key. EPSS estimates a 0.68% chance of exploitation in the next 30 days.
Description
JumpServer is an open source bastion host. As an unauthenticated user, it is possible to authenticate to the core API with a username and an SSH public key without needing a password or the corresponding SSH private key. An SSH public key should be considered public knowledge and should not used as an authentication secret alone. JumpServer provides an API for the KoKo component to validate user private key logins. This API does not verify the source of requests and will generate a personal authentication token. Given that public keys can be easily leaked, an attacker can exploit the leaked public key and username to authenticate, subsequently gaining access to the current user's information and authorized actions. This issue has been addressed in versions 2.28.20 and 3.7.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Fit2cloud | Jumpserver | >= 2.0.0, < 2.28.20 |
| Fit2cloud | Jumpserver | >= 3.0.0, < 3.7.1 |
References
- https://github.com/jumpserver/jumpserver/security/advisories/GHSA-fr8h-xh5x-r8g9Exploit, Vendor Advisory
- https://github.com/jumpserver/jumpserver/security/advisories/GHSA-fr8h-xh5x-r8g9Exploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2023-43652?
How severe is CVE-2023-43652?
How do I fix CVE-2023-43652?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-43647baserCMS is a website development framework. Prior to versio…5.4
- CVE-2023-43648baserCMS is a website development framework. Prior to versio…6.5
- CVE-2023-43649baserCMS is a website development framework. Prior to versio…9.8
- CVE-2023-4365Inappropriate implementation in Fullscreen in Google Chrome …4.3
- CVE-2023-43650JumpServer is an open source bastion host. The verification …7.4
- CVE-2023-43651JumpServer is an open source bastion host. An authenticated …9.9
- CVE-2023-43654TorchServe is a tool for serving and scaling PyTorch models …9.8
- CVE-2023-43655Composer is a dependency manager for PHP. Users publishing a…8.8
- CVE-2023-43656matrix-hookshot is a Matrix bot for connecting to external s…9
- CVE-2023-43657discourse-encrypt is a plugin that provides a secure communi…6.1
- CVE-2023-43658dicourse-calendar is a plugin for the Discourse messaging pl…6.1
- CVE-2023-43659Discourse is an open source platform for community discussio…5.4
Are you affected by CVE-2023-43652?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
