JumpServer Koko vulnerable to Command Injection for Kubernetes Connection
CVE-2023-28110
5.7MEDIUM
What is CVE-2023-28110?
The Jumpserver Koko component, an essential part of its open-source bastion host system, is vulnerable prior to version 2.28.8. Attackers exploiting this vulnerability can utilize illegal tokens to gain unauthorized access to a Kubernetes cluster, leading to potential command execution that may disrupt the Koko container environment and impair its normal functionality. This risk highlights the importance of updating to the patched version 2.28.8 to ensure a secure operational environment.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
jumpserver < 2.28.8
References
CVSS V3.1
Score:
5.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
