漏洞编号:CVE-2021-3169
存在漏洞的服务或平台:飞致云:JumpServer
存在该漏洞的服务或平台的详细信息:
JumpServer = v1.5.9
v2.4.0 < JumpServer < v2.4.5
v2.5.0 < JumpServer < v2.5.4
v2.6.0 < JumpServer < v2.6.2
The Markdown Article Follows:
Vulnerability Description
JumpServer is the world's first fully open-source bastion host. It uses the GNU GPL v2.0 open-source license and is a professional operations audit system that complies with 4A. On January 15, 2021, Feizhiyun officially released a security update that fixed a remote command execution vulnerability. Because certain JumpServer interfaces did not impose authorization restrictions, an attacker could construct malicious requests to obtain sensitive log information, thereby gaining control of all the machines within it and executing arbitrary commands.
Cause of the Vulnerability
Scope of Impact
JumpServer = v1.5.9 v2.4.0 < JumpServer < v2.4.5 v2.5.0 < JumpServer < v2.5.4 v2.6.0 < JumpServer < v2.6.2