SSH public key login without private key challenge if mfa is enabled in jumpserver
CVE-2023-42818
9.8CRITICAL
What is CVE-2023-42818?
JumpServer, an open-source bastion host, is affected by a vulnerability that arises when multi-factor authentication (MFA) is enabled alongside the usage of public keys for authentication. The Koko SSH server does not properly verify the corresponding SSH private key, leading to a risk where an attacker could exploit this flaw using a disclosed public key to conduct brute-force attacks against the SSH service. This security concern necessitates upgrading to patched versions 3.6.5 and 3.5.6 to mitigate risks. There are no workarounds available for this issue.
Affected Version(s)
jumpserver >= 3.6.0, < 3.6.5 < 3.6.0, 3.6.5
jumpserver < 3.5.6 < 3.5.6
