Skip to content
COOEY

EXPOSURES › CVE-2023-48193

CVE-2023-48193

CRITICAL
DETAIL
SourceNVD · cve Published2023-11-28 CVSS9.8 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-48193 ↗
⚡ RCE SHAME 50/100 rce

Insecure Permissions vulnerability in JumpServer GPLv3 v.3.8.0 allows a remote attacker to execute arbitrary code via bypassing the command filtering function. NOTE: this is disputed because command filtering is not intended to restrict what code can be run by authorized users wh

▸ RECOMMENDED ACTION  Remote code execution — patch the affected products on priority.

DESCRIPTION

Insecure Permissions vulnerability in JumpServer GPLv3 v.3.8.0 allows a remote attacker to execute arbitrary code via bypassing the command filtering function. NOTE: this is disputed because command filtering is not intended to restrict what code can be run by authorized users who are allowed to execute files.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.