JumpServer is an open source bastion host and an operation and maintenance security audit system. From 4.8.0 until 4.10.17, an authenticated user with SFTP permission to an authorized asset can submi…
Medium CVSS 5.4
Summary
JumpServer is an open source bastion host and an operation and maintenance security audit system. From 4.8.0 until 4.10.17, an authenticated user with SFTP permission to an authorized asset can submit crafted traversal paths through the KoKo Web Terminal SFTP feature, causing AssetDir.GetRealPath() in pkg/srvconn/sftp_asset.go to resolve paths outside the intended SFTP root and permit read, list, write, rename, or delete operations under the configured backend account on that asset. This issue …
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://github.com/jumpserver/jumpserver/security/advisories/GHSA-x6rg-36j6-76vr
- https://github.com/jumpserver/koko/commit/02fabebe27dacce89114fba122c667a946fd12ea
- https://github.com/jumpserver/koko/releases/tag/v4.10.17
Timeline
- nvd_ingest NVD