VendorsFIT2CLOUDjumpserverall versions
Vulnerabilities

FIT2CLOUD JumpServer

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

24CVEs
CVE-2024-40629
Arbitrary File Write in Ansible Playbooks leads to RCE in Jumpserver
Published 2024-07-18 · Modified
10.0EPSS 0.013
CVE-2024-40628
Arbitrary File Read in Ansible Playbooks in Jumpserver
Published 2024-07-18 · Modified
10.0EPSS 0.009
CVE-2024-29202
JumpServer vulnerable to Jinja2 template injection in Ansible leads to RCE in Celery
Published 2024-03-29 · Modified
9.9EPSS 0.059
CVE-2024-29201
JumpServer's insecure Ansible playbook validation leads to RCE in Celery
Published 2024-03-29 · Modified
9.9EPSS 0.059
CVE-2023-43651
Remote code execution on the host system via MongoDB shell in jumpserver
Published 2023-09-27 · Modified
9.9EPSS 0.017
CVE-2023-28110
JumpServer Koko vulnerable to Command Injection for Kubernetes Connection
Published 2023-03-16 · Modified
9.9EPSS 0.008
CVE-2023-48193
Insecure Permissions vulnerability in JumpServer GPLv3 v.3.8.0 allows a remote attacker to execute arbitrary code via bypassing the command filtering function. NOTE: this is disputed because command filtering is not intended to restrict what code can be run by authorized users who are allowed to execute files.
Published 2023-11-28 · Modified
9.8EPSS 0.020
CVE-2023-42818
SSH public key login without private key challenge if mfa is enabled in jumpserver
Published 2023-09-27 · Modified
9.8EPSS 0.006
CVE-2025-62712
JumpServer Connection Token Leak Vulnerability
Published 2025-10-30 · Analyzed
9.6EPSS 0.005
CVE-2023-43652
Non-MFA account takeover via using only SSH public key to login in jumpserver
Published 2023-09-27 · Analyzed
9.1EPSS 0.007
CVE-2023-42819
Path traversal in Jumpserver
Published 2023-09-26 · Modified
8.9EPSS 0.019
CVE-2023-42442
JumpServer session replays download without authentication
Published 2023-09-15 · Modified
8.2EPSS 0.585
CVE-2023-42820
Random seed leakage in Jumpserver
Published 2023-09-26 · Modified
8.2EPSS 0.054
CVE-2023-43650
Non-MFA account takeover via brute-force attack on weak password reset code in jumpserver
Published 2023-09-27 · Analyzed
8.2EPSS 0.005
CVE-2025-62795
JumpServer Unauthorized LDAP Configuration Access via WebSocket
Published 2025-10-30 · Analyzed
7.1EPSS 0.003
CVE-2026-31864
JumpServer has a Server-Side Template Injection Leading to RCE via YAML Rendering
Published 2026-03-13 · Analyzed
6.8EPSS 0.005
CVE-2024-24763
JumpServer Open Redirect Vulnerability
Published 2024-02-20 · Analyzed
6.1EPSS 0.011
CVE-2025-58044
JumpServer has an Open Redirect Vulnerability
Published 2025-12-01 · Analyzed
6.1EPSS 0.005
CVE-2023-46123
jumpserver is vulnerable to password brute-force protection bypass via arbitrary IP values
Published 2023-10-25 · Modified
5.3EPSS 0.007
CVE-2023-46138
JumpServer default admin user email leak password reset
Published 2023-10-30 · Modified
5.3EPSS 0.003
CVE-2024-29020
JumpServer allows nn authorized attacker to get sensitive information in playbook files when playbook_id is leaked
Published 2024-03-29 · Analyzed
5.3EPSS 0.003
CVE-2024-29024
JumpServer Direct Object Reference (IDOR) Vulnerability in File Manager Bulk Transfer Functionality
Published 2024-03-29 · Analyzed
5.3EPSS 0.002
CVE-2026-31798
JumpServer Improper Certificate Validation in Custom SMS API Client
Published 2026-03-13 · Analyzed
5.0EPSS 0.001
CVE-2025-27095
JumpServer has a Kubernetes Token Leak Vulnerability
Published 2025-03-31 · Analyzed
4.3EPSS 0.003