Critical severity9.8NVD Advisory· Published Jul 23, 2021· Updated Jun 17, 2026
CVE-2021-3169
CVE-2021-3169
Description
An issue in Jumpserver before 2.6.2, before 2.5.4, before 2.4.5 allows attackers to create a connection token through an API which does not have access control and use it to access sensitive assets.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:jumpserver:jumpserver:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:jumpserver:jumpserver:*:*:*:*:*:*:*:*range: >=2.4.0,<2.4.5
- (no CPE)range: <2.6.2, <2.5.4, <2.4.5
- Jumpserver/Jumpserverdescription
Patches
Vulnerability mechanics
References
3- blog.fit2cloud.comnvdThird Party Advisory
- mp.weixin.qq.com/s/5tgcaIrnDnGP-LvWPw9YCgnvdThird Party Advisory
- s.tencent.com/research/bsafe/1228.htmlnvdThird Party Advisory
News mentions
0No linked articles in our index yet.