PT-2023-28901 · Unknown · Jumpserver

Oskar-Zeinomahmalat-Sonarsource

·

Published

2023-09-27

·

Updated

2025-04-21

·

CVE-2023-43650

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions JumpServer versions prior to 2.28.20 JumpServer versions prior to 3.7.1
Description The verification code for resetting a user's password in JumpServer is vulnerable to brute-force attacks due to the absence of rate limiting. This allows for up to 1,000,000 validation attempts within a 1-minute window. The issue is related to the 6-digit verification code sent to users to facilitate password reset.
Recommendations For versions prior to 2.28.20, upgrade to version 2.28.20 or later. For versions prior to 3.7.1, upgrade to version 3.7.1 or later. As a temporary workaround, consider implementing rate limiting on the password reset feature until a patch is available. Restrict access to the password reset functionality to minimize the risk of exploitation.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2023-43650
GHSA-MWX4-8FWC-2XVW

Affected Products

Jumpserver