Description

JumpServer is an open source bastion host and an operation and maintenance security audit system. An authenticated user can exploit the Insecure Direct Object Reference (IDOR) vulnerability in the file manager's bulk transfer by manipulating job IDs to upload malicious files, potentially compromising the integrity and security of the system. This vulnerability is fixed in v3.10.6.

INFO

Published Date :

2024-03-29T14:45:56.377Z

Last Modified :

2024-08-02T01:03:51.546Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2024-29024 vulnerability.

Vendors Products
Fit2cloud
  • Jumpserver
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2024-29024.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact