S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 8, 2024

CVE-2023-42442 Scanner

Detects 'Improper Access Control' vulnerability in JumpServer affects v. from 3.0.0 before 3.5.5 and 3.6.x before 3.6.4.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3k
Times Used
continuous scan runs
3.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-42442
5.3
CVSShigh
Exploitable remotely over the internet · no authentication required.

JumpServer is an open source bastion host and a professional operation and maintenance security audit system. Starting in version 3.0.0 and prior to versions 3.5.5 and 3.6.4, session replays can download without authentication. Session replays stored in S3, OSS, or other cloud storage are not affected. The api `/api/v1/terminal/sessions/` permission control is broken and can be accessed anonymously. SessionViewSet permission classes set to `[RBACPermission | IsSessionAssignee]`, relation is or, so any permission matched will be allowed. Versions 3.5.5 and 3.6.4 have a fix. After upgrading, visit the api `$HOST/api/v1/terminal/sessions/?limit=1`. The expected http response code is 401 (`not_authenticated`).

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
jumpserverby jumpserver
>= 3.0.0, < 3.5.5
Updated Aug 22, 2026View on NVD →
Detail

JumpServer is an indispensable open source bastion host and a professional operation and maintenance security audit system used for monitoring and managing remote servers. With JumpServer, IT teams can secure and streamline their infrastructure and protect it against unauthorized access or attacks. 

Recently, a critical vulnerability has been detected in JumpServer versions prior to 3.5.5 and 3.6.4, namely the CVE-2023-42442. This vulnerability allows attackers to download session replays without authentication, which poses a serious security risk to the infrastructure. In other words, attackers can gain access to sensitive information and possibly even take over the system. 

The exploitation of this vulnerability can lead to severe consequences such as data breaches, unauthorized access, and even complete system compromise. In addition, it can also threaten the privacy, confidentiality, and integrity of sensitive information, putting the organization's reputation and compliance with regulations at risk. For this reason, it is imperative to take proactive measures to mitigate this vulnerability immediately. 

Thanks to the pro features of s4e.io, you can easily and quickly learn about vulnerabilities in your digital assets and take the necessary measures to protect your infrastructure. With advanced scanning and reporting capabilities, you can detect vulnerabilities, prioritize them based on their severity, and receive actionable recommendations to mitigate them. Additionally, you can set up alerts to be notified of any potential threat in real-time and stay ahead of cyber threats.

 

REFERENCES

Solution Advice

To prevent such attacks, it is recommended to take the following precautions, among others:

  • Update JumpServer to versions 3.5.5 or 3.6.4 to benefit from the fix.
  • Strengthen authentication mechanisms and enable two-factor authentication to ensure that only authorized users have access to the system.
  • Regularly monitor and audit system logs for suspicious activities and unauthorized access attempts.
  • Use access control and permission mechanisms to limit access to sensitive information and resources.
  • Regularly assess and test the system's security posture and implement security best practices and guidelines.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.