CVE Vulnerabilities

CVE-2023-48193

Published: Nov 28, 2023 | Modified: Jun 11, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Insecure Permissions vulnerability in JumpServer GPLv3 v.3.8.0 allows a remote attacker to execute arbitrary code via bypassing the command filtering function. NOTE: this is disputed because command filtering is not intended to restrict what code can be run by authorized users who are allowed to execute files.

Affected Software

Name Vendor Start Version End Version
Jumpserver Fit2cloud 3.8.0 (including) 3.8.0 (including)

References