CVE-2024-24763: JumpServer Open Redirect Vulnerability
JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to version 3.10.0, attackers can exploit this vulnerability to construct malicious links, leading users to click on them, thereby facilitating phishing attacks or cross-site scripting attacks. Version 3.10.0 contains a patch for this issue. No known workarounds are available.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
JumpServerto a version that resolves this vulnerability.Fixed in 3.10.0
Event History
Frequently Asked Questions
What is the severity of CVE-2024-24763?
CVE-2024-24763 is classified as a high severity vulnerability due to its potential to facilitate phishing attacks.
How do I fix CVE-2024-24763?
To remediate CVE-2024-24763, upgrade to JumpServer version 3.10.0 or later.
What kind of attacks can CVE-2024-24763 facilitate?
CVE-2024-24763 can facilitate phishing attacks and cross-site scripting (XSS) attacks.
Which versions of JumpServer are affected by CVE-2024-24763?
CVE-2024-24763 affects all JumpServer versions prior to 3.10.0.
Is there a patch available for CVE-2024-24763?
Yes, upgrading to JumpServer version 3.10.0 includes the fix for CVE-2024-24763.