PT-2024-22674 · Unknown · Jumpserver
Ilyazavyalov
·
Published
2024-03-29
·
Updated
2025-01-09
·
CVE-2024-29020
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
JumpServer versions prior to 3.10.6
Description
An authorized attacker can obtain sensitive information contained within playbook files if they manage to learn the
playbook id of another user. This breach of confidentiality can lead to information disclosure and exposing sensitive data.Recommendations
For versions prior to 3.10.6, update to version 3.10.6 to resolve the issue. As a temporary workaround, consider restricting access to playbook files and limiting the ability for authorized attackers to learn the
playbook id of other users.Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jumpserver