CVE-2021-3169
23.07.2021, 21:15
An issue in Jumpserver before 2.6.2, before 2.5.4, before 2.4.5 allows attackers to create a connection token through an API which does not have access control and use it to access sensitive assets.
Vendor | Product | Version |
---|---|---|
jumpserver | jumpserver | 2.4.0 ≤ 𝑥 < 2.4.5 |
jumpserver | jumpserver | 2.5.0 ≤ 𝑥 < 2.5.4 |
jumpserver | jumpserver | 2.6.0 ≤ 𝑥 < 2.6.2 |
𝑥
= Vulnerable software versions