CVE-2024-40628

JumpServer is an open-source Privileged Access Management (PAM) tool that provides DevOps and IT teams with on-demand and secure access to SSH, RDP, Kubernetes, Database and RemoteApp endpoints through a web browser. An attacker can exploit the ansible playbook to read arbitrary files in the celery container, leading to sensitive information disclosure. The Celery container runs as root and has database access, allowing the attacker to steal all secrets for hosts, create a new JumpServer account with admin privileges, or manipulate the database in other ways. This issue has been addressed in release versions 3.10.12 and 4.0.0. It is recommended to upgrade the safe versions. There is no known workarounds for this vulnerability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:fit2cloud:jumpserver:*:*:*:*:*:*:*:*

History

21 Nov 2024, 09:31

Type Values Removed Values Added
References () https://github.com/jumpserver/jumpserver/security/advisories/GHSA-rpf7-g4xh-84v9 - Vendor Advisory () https://github.com/jumpserver/jumpserver/security/advisories/GHSA-rpf7-g4xh-84v9 - Vendor Advisory
CVSS v2 : unknown
v3 : 9.1
v2 : unknown
v3 : 10.0

10 Sep 2024, 19:46

Type Values Removed Values Added
CPE cpe:2.3:a:fit2cloud:jumpserver:*:*:*:*:*:*:*:*
First Time Fit2cloud
Fit2cloud jumpserver
References () https://github.com/jumpserver/jumpserver/security/advisories/GHSA-rpf7-g4xh-84v9 - () https://github.com/jumpserver/jumpserver/security/advisories/GHSA-rpf7-g4xh-84v9 - Vendor Advisory
CVSS v2 : unknown
v3 : 10.0
v2 : unknown
v3 : 9.1

19 Jul 2024, 13:01

Type Values Removed Values Added
Summary
  • (es) JumpServer es una herramienta de gestión de acceso privilegiado (PAM) de código abierto que proporciona a los equipos de TI y DevOps acceso seguro y bajo demanda a terminales SSH, RDP, Kubernetes, bases de datos y RemoteApp a través de un navegador web. Un atacante puede aprovechar el libro de jugadas de ansible para leer archivos arbitrarios en el contenedor de apio, lo que lleva a la divulgación de información confidencial. El contenedor Celery se ejecuta como root y tiene acceso a la base de datos, lo que permite al atacante robar todos los secretos de los hosts, crear una nueva cuenta JumpServer con privilegios de administrador o manipular la base de datos de otras formas. Este problema se solucionó en las versiones 3.10.12 y 4.0.0. Se recomienda actualizar las versiones seguras. No se conocen workarounds para esta vulnerabilidad.

18 Jul 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-18 17:15

Updated : 2024-11-21 09:31


NVD link : CVE-2024-40628

Mitre link : CVE-2024-40628

CVE.ORG link : CVE-2024-40628


JSON object : View

Products Affected

fit2cloud

  • jumpserver
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')