JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to 4.10.17, an authenticated administrator with Applet Host management and deployment permissio…
中危 CVSS 6.7
摘要
JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to 4.10.17, an authenticated administrator with Applet Host management and deployment permissions can inject Jinja2 expressions into the IP/Host field or Core Service Address field, causing Ansible to evaluate ansible_host inventory data or playbook variables during Applet Host deployment and execute arbitrary commands on the JumpServer control node. This issue is fixed in version 4.10.17.
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
数据来源
- NVD DATABASE
原始链接
- https://github.com/jumpserver/jumpserver/commit/cc57ba0de5f6015746fae11cfc62402b11618e59
- https://github.com/jumpserver/jumpserver/pull/16749
- https://github.com/jumpserver/jumpserver/pull/16886
- https://github.com/jumpserver/jumpserver/releases/tag/v4.10.17
- https://github.com/jumpserver/jumpserver/security/advisories/GHSA-22h6-pcgh-9v7q
时间线
- nvd_ingest NVD