PT-2023-29856 · Unknown · Jumpserver

Oskar-Zeinomahmalat-Sonarsource

·

Published

2023-10-24

·

Updated

2025-03-25

·

CVE-2023-46123

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions jumpserver versions prior to 3.8.0
Description A flaw in the Core API of jumpserver allows attackers to bypass password brute-force protections by spoofing arbitrary IP addresses. This enables attackers to make unlimited password attempts by altering their apparent IP address for each request.
Recommendations For versions prior to 3.8.0, update to version 3.8.0 to resolve the issue. As a temporary workaround, consider restricting access to the Core API to minimize the risk of exploitation. Avoid using the API for password attempts until the issue is resolved.

Exploit

Fix

Improper Restriction of Excessive Authentication Attempts

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-46123
GHSA-HVW4-766M-P89F

Affected Products

Jumpserver