EXPOSURES › CVE-2023-48193
CVE-2023-48193
CRITICAL
DETAIL
SourceNVD · cve
Published2023-11-28
CVSS9.8
Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-48193 ↗
⚡ RCE
SHAME 50/100
rce
Insecure Permissions vulnerability in JumpServer GPLv3 v.3.8.0 allows a remote attacker to execute arbitrary code via bypassing the command filtering function. NOTE: this is disputed because command filtering is not intended to restrict what code can be run by authorized users wh
▸ RECOMMENDED ACTION Remote code execution — patch the affected products on priority.
PLAYERS IMPLICATED
DESCRIPTION
Insecure Permissions vulnerability in JumpServer GPLv3 v.3.8.0 allows a remote attacker to execute arbitrary code via bypassing the command filtering function. NOTE: this is disputed because command filtering is not intended to restrict what code can be run by authorized users who are allowed to execute files.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.