CVE-2025-58044
Last modified
CVE-2025-58044 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v3.10.19 and v4.10.5, The /core/i18n// endpoint uses the Referer header as the redirection target without proper validation, which could lead to an Open Redirect vulnerability. EPSS estimates a 0.44% chance of exploitation in the next 30 days.
Description
JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v3.10.19 and v4.10.5, The /core/i18n// endpoint uses the Referer header as the redirection target without proper validation, which could lead to an Open Redirect vulnerability. This vulnerability is fixed in v3.10.19 and v4.10.5.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Fit2cloud | Jumpserver | < 3.10.19 |
| Fit2cloud | Jumpserver | >= 4.0.0, < 4.10.5 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-58044?
How severe is CVE-2025-58044?
How do I fix CVE-2025-58044?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-58039Rejected reason: Not used
- CVE-2025-5804Improper Control of Filename for Include/Require Statement i…7.5
- CVE-2025-58040Rejected reason: Not used
- CVE-2025-58041Rejected reason: Not used
- CVE-2025-58042Rejected reason: Not used
- CVE-2025-58043Rejected reason: Not used
- CVE-2025-58045Dataease is an open source data analytics and visualization …9.8
- CVE-2025-58046Dataease is an open-source data visualization and analysis p…9.8
- CVE-2025-58047Volto is a React based frontend for the Plone Content Manage…7.5
- CVE-2025-58048Paymenter is a free and open-source webshop solution for hos…9.9
- CVE-2025-58049XWiki Platform is a generic wiki platform offering runtime s…7.5
- CVE-2025-5805Missing Authorization vulnerability in Ninetheme Electron el…6.5
Are you affected by CVE-2025-58044?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
