Jumpserver是JumpServer公司开源的一款运维审计堡垒机。 Jumpserver 4.10.17之前版本存在授权问题漏洞,该漏洞源于具有users.invite_user权限的用户可通过向/api/v1/users/users/invite/接口提交现有成员,导致组织邀请逻辑执行user.org_roles.set(org_roles)并替换成员现有组织角色,可能导致权限提升或降级管理员。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| jumpserver | jumpserver | < 4.10.17 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| jumpserver | jumpserver | < 4.10.17 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-44845 | 6.7 MEDIUM | JumpServer: Remote Command Execution (RCE) via Jinja Template Injection in Applet Host Dep |
| CVE-2026-54336 | 5.4 MEDIUM | JumpServer: KoKo Web Terminal SFTP Path Traversal on Authorized Asset |
No comments yet