CVE-2025-62712: JumpServer Connection Token Leak Vulnerability
JumpServer is an open source bastion host and an operation and maintenance security audit system. In JumpServer versions prior to v3.10.20-lts and v4.10.11-lts, an authenticated, non-privileged user can retrieve connection tokens belonging to other users via the super-connection API endpoint (/api/v1/authentication/super-connection-token/). When accessed from a web browser, this endpoint returns connection tokens created by all users instead of restricting results to tokens owned by or authorized for the requester. An attacker who obtains these tokens can use them to initiate connections to managed assets on behalf of the original token owners, resulting in unauthorized access and privilege escalation across sensitive systems. This vulnerability is fixed in v3.10.20-lts and v4.10.11-lts.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62712?
CVE-2025-62712 has been classified with a medium severity due to the potential for unauthorized access to sensitive connection tokens.
How do I fix CVE-2025-62712?
To resolve CVE-2025-62712, upgrade JumpServer to version 3.10.20-lts or 4.10.11-lts or later.
Who is affected by CVE-2025-62712?
CVE-2025-62712 affects users of JumpServer versions prior to 3.10.20-lts and 4.10.11-lts.
What is the impact of CVE-2025-62712?
The impact of CVE-2025-62712 allows authenticated, non-privileged users to access and retrieve connection tokens belonging to other users.
What systems should be monitored for CVE-2025-62712?
Systems running JumpServer versions earlier than 3.10.20-lts or 4.10.11-lts should be monitored and updated to mitigate CVE-2025-62712.