SSH public key login without private key challenge if mfa is enabled in jumpserver
CVE-2023-42818
What is CVE-2023-42818?
JumpServer, an open-source bastion host, is affected by a vulnerability that arises when multi-factor authentication (MFA) is enabled alongside the usage of public keys for authentication. The Koko SSH server does not properly verify the corresponding SSH private key, leading to a risk where an attacker could exploit this flaw using a disclosed public key to conduct brute-force attacks against the SSH service. This security concern necessitates upgrading to patched versions 3.6.5 and 3.5.6 to mitigate risks. There are no workarounds available for this issue.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
jumpserver >= 3.6.0, < 3.6.5 < 3.6.0, 3.6.5
jumpserver < 3.5.6 < 3.5.6
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
