Sensitive Information Disclosure Vulnerability in JumpServer
CVE-2024-29020

5.3MEDIUM

Key Information:

Vendor

Jumpserver

Vendor
CVE Published:
29 March 2024

What is CVE-2024-29020?

JumpServer is an open source bastion host and an operation and maintenance security audit system. An authorized attacker can obtain sensitive information contained within playbook files if they manage to learn the playbook_id of another user. This breach of confidentiality can lead to information disclosure and exposing sensitive data. This vulnerability is fixed in v3.10.6.

Affected Version(s)

jumpserver >= 3.0.0, <= 3.10.5

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.