← Back

CVE-2024-29024

nvd nist
Published: Mar 29, 2024Modified: Jan 9, 2025

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
Exploitability: 1.6 / Impact: 3.6
Source: NVD

Description

JumpServer is an open source bastion host and an operation and maintenance security audit system. An authenticated user can exploit the Insecure Direct Object Reference (IDOR) vulnerability in the file manager's bulk transfer by manipulating job IDs to upload malicious files, potentially compromising the integrity and security of the system. This vulnerability is fixed in v3.10.6.

Affected (1)

1 product
Jumpserver
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 3.0.0 to 3.10.6

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.