Vulnerability CVE-2021-3169


Published: 2021-07-23

Description:
An issue in Jumpserver 2.6.2 and below allows attackers to create a connection token through an API which does not have access control and use it to access sensitive assets.

 References:
https://mp.weixin.qq.com/s/5tgcaIrnDnGP-LvWPw9YCg
https://s.tencent.com/research/bsafe/1228.html
https://blog.fit2cloud.com/?p=1764

Copyright 2024, cxsecurity.com

 

Back to Top