Jumpserver是JumpServer公司开源的一款运维审计堡垒机。 Jumpserver 4.8.0版本至4.10.17之前版本存在路径遍历漏洞,该漏洞源于KoKo Web Terminal SFTP功能对特制路径处理不当,可能导致路径遍历,并允许已认证用户在已授权资产上以配置的后台账户执行读取、列表、写入、重命名或删除操作。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| jumpserver | jumpserver | >= 4.8.0, < 4.10.17 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| jumpserver | jumpserver | >= 4.8.0, < 4.10.17 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-44845 | 6.7 MEDIUM | JumpServer: Remote Command Execution (RCE) via Jinja Template Injection in Applet Host Dep |
| CVE-2026-44846 | 6.2 MEDIUM | JumpServer: Privilege Overwrite via Organization Invite Logic Flaw |
No comments yet