Known Vulnerabilities for Jumpserver by Fit2cloud
Listed below are 10 of the newest known vulnerabilities associated with "Jumpserver" by "Fit2cloud".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-54336 json | JumpServer is an open source bastion host and an operation and maintenance security audit system. From 4.8.0 until 4.10.17, a... | Not Provided | 2026-08-17 | 2026-08-18 |
| CVE-2026-44846 json | JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to 4.10.17, a user wi... | Not Provided | 2026-08-17 | 2026-08-18 |
| CVE-2026-44845 json | JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to 4.10.17, an authen... | Not Provided | 2026-08-17 | 2026-08-18 |
| CVE-2023-48193 json | Insecure Permissions vulnerability in JumpServer GPLv3 v.3.8.0 allows a remote attacker to execute arbitrary code via bypassi... | Not Provided | 2023-11-28 | 2026-07-09 |
| CVE-2023-46138 json | JumpServer is an open source bastion host and maintenance security audit system that complies with 4A specifications. Prior t... | 5.3 - MEDIUM | 2023-10-31 | 2023-11-08 |
| CVE-2023-46123 json | jumpserver is an open source bastion machine, professional operation and maintenance security audit system that complies with... | 5.3 - MEDIUM | 2023-10-25 | 2023-11-01 |
| CVE-2023-43652 json | JumpServer is an open source bastion host. As an unauthenticated user, it is possible to authenticate to the core API with a ... | 9.1 - CRITICAL | 2023-09-27 | 2023-10-02 |
| CVE-2023-43651 json | JumpServer is an open source bastion host. An authenticated user can exploit a vulnerability in MongoDB sessions to execute a... | 9.9 - CRITICAL | 2023-09-27 | 2023-10-02 |
| CVE-2023-43650 json | JumpServer is an open source bastion host. The verification code for resetting user's password is vulnerable to brute-force a... | 7.4 - HIGH | 2023-09-27 | 2023-10-02 |
| CVE-2023-42820 json | JumpServer is an open source bastion host. This vulnerability is due to exposing the random number seed to the API, potential... | 8.2 - HIGH | 2023-09-27 | 2023-09-29 |