VYPR

Jumpserver

by Jumpserver

Source repositories

CVEs (26)

  • CVE-2025-58044MedDec 1, 2025
    risk 0.00cvss 6.1epss 0.01

    JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v3.10.19 and v4.10.5, The /core/i18n// endpoint uses the Referer header as the redirection target without proper validation, which could lead to an Open Redirect…

  • CVE-2025-62712CriOct 30, 2025
    risk 0.00cvss 9.6epss 0.00

    JumpServer is an open source bastion host and an operation and maintenance security audit system. In JumpServer versions prior to v3.10.20-lts and v4.10.11-lts, an authenticated, non-privileged user can retrieve connection tokens belonging to other users via the super-connection…

  • CVE-2023-46138LowOct 31, 2023
    risk 0.00cvss 3.7epss 0.00

    JumpServer is an open source bastion host and maintenance security audit system that complies with 4A specifications. Prior to version 3.8.0, the default email for initial user admin is `admin[@]mycompany[.]com`, and users reset their passwords by sending an email. Currently,…

  • CVE-2023-42820HigSep 27, 2023
    risk 0.00cvss 7.0epss 0.05

    JumpServer is an open source bastion host. This vulnerability is due to exposing the random number seed to the API, potentially allowing the randomly generated verification codes to be replayed, which could lead to password resets. If MFA is enabled users are not affect. Users…

  • CVE-2023-42819HigSep 27, 2023
    risk 0.00cvss 8.9epss 0.02

    JumpServer is an open source bastion host. Logged-in users can access and modify the contents of any file on the system. A user can use the 'Job-Template' menu and create a playbook named 'test'. Get the playbook id from the detail page, like…

  • CVE-2022-42225MedMay 24, 2023
    risk 0.00cvss 5.4epss 0.01

    Jumpserver 2.10.0 <= version <= 2.26.0 contains multiple stored XSS vulnerabilities because of improper filtering of user input, which can execute any javascript under admin's permission.

Page 2 of 2