PT-2023-21569 · Unknown · Jumpserver

Published

2023-03-16

·

Updated

2023-03-23

·

CVE-2023-28110

CVSS v3.1

5.7

Medium

VectorAV:N/AC:H/PR:H/UI:R/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jumpserver versions prior to 2.28.8
Description The issue affects Jumpserver, a popular open source bastion host, specifically its Koko component, which is the Go version of coco. It allows the execution of dangerous commands when using illegal tokens to connect to a Kubernetes cluster, potentially disrupting the Koko container environment and affecting normal usage.
Recommendations For versions prior to 2.28.8, update to version 2.28.8 to resolve the issue. As a temporary workaround, consider restricting access to the Koko component to minimize the risk of exploitation.

Exploit

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-28110
GHSA-6X5P-JM59-JH29

Affected Products

Jumpserver