CVE-2025-58044
01.12.2025, 21:15
JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v3.10.19 and v4.10.5, The /core/i18n// endpoint uses the Referer header as the redirection target without proper validation, which could lead to an Open Redirect vulnerability. This vulnerability is fixed in v3.10.19 and v4.10.5.
| Vendor | Product | Version |
|---|---|---|
| fit2cloud | jumpserver | 𝑥 < 3.10.19 |
| fit2cloud | jumpserver | 4.0.0 ≤ 𝑥 < 4.10.5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration