CVE-2025-62795: JumpServer Unauthorized LDAP Configuration Access via WebSocket
JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v3.10.21-lts and v4.10.12-lts, a low-privileged authenticated user can invoke LDAP configuration tests and start LDAP synchronization by sending crafted messages to the /ws/ldap/ WebSocket endpoint, bypassing authorization checks and potentially exposing LDAP credentials or causing unintended sync operations. This vulnerability is fixed in v3.10.21-lts and v4.10.12-lts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62795?
CVE-2025-62795 has a low severity level due to the nature of the vulnerability being exploitable only by low-privileged authenticated users.
How do I fix CVE-2025-62795?
To fix CVE-2025-62795, upgrade JumpServer to version 3.10.21-lts or 4.10.12-lts or later.
What are the affected versions for CVE-2025-62795?
CVE-2025-62795 affects JumpServer versions prior to 3.10.21-lts and 4.10.12-lts.
Who can exploit CVE-2025-62795?
CVE-2025-62795 can be exploited by low-privileged authenticated users who can send crafted messages.
What type of attacks does CVE-2025-62795 allow?
CVE-2025-62795 allows low-privileged authenticated users to invoke LDAP configuration tests and initiate LDAP synchronization.