CVE-2021-3169: Critical severity Jumpserver Jumpserver vulnerability
An issue in Jumpserver 2.6.2 and below allows attackers to create a connection token through an API which does not have access control and use it to access sensitive assets.
Other sources
An issue in Jumpserver before 2.6.2, before 2.5.4, before 2.4.5 allows attackers to create a connection token through an API which does not have access control and use it to access sensitive assets.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-3169?
CVE-2021-3169 is classified as a high-severity vulnerability due to the potential for unauthorized access to sensitive assets.
How do I fix CVE-2021-3169?
To fix CVE-2021-3169, update Jumpserver to a version later than 2.6.2.
What is the impact of CVE-2021-3169?
The impact of CVE-2021-3169 includes the ability for attackers to create unauthorized connection tokens and access sensitive information.
Which versions of Jumpserver are affected by CVE-2021-3169?
Jumpserver versions 2.6.2 and below are affected by CVE-2021-3169.
What is the exploit vector for CVE-2021-3169?
The exploit vector for CVE-2021-3169 involves making API calls that lack proper access control.