Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

x/vulndb: potential Go vuln in github.com/jumpserver/jumpserver: CVE-2024-40629 #3577

Open
GoVulnBot opened this issue Mar 25, 2025 · 0 comments

Comments

@GoVulnBot
Copy link

Advisory CVE-2024-40629 references a vulnerability in the following Go modules:

Module
github.com/jumpserver/jumpserver

Description:
JumpServer is an open-source Privileged Access Management (PAM) tool that provides DevOps and IT teams with on-demand and secure access to SSH, RDP, Kubernetes, Database and RemoteApp endpoints through a web browser. An attacker can exploit the Ansible playbook to write arbitrary files, leading to remote code execution (RCE) in the Celery container. The Celery container runs as root and has database access, allowing an attacker to steal all secrets for hosts, create a new JumpServer account with admin privileges, or manipulate the database in other ways. This issue has been patched in release ...

References:

No existing reports found with this module or alias.
See doc/quickstart.md for instructions on how to triage this report.

id: GO-ID-PENDING
modules:
    - module: github.com/jumpserver/jumpserver
      vulnerable_at: 4.8.0+incompatible
summary: CVE-2024-40629 in github.com/jumpserver/jumpserver
cves:
    - CVE-2024-40629
references:
    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2024-40629
    - web: https://github.com/jumpserver/jumpserver/security/advisories/GHSA-3wgp-q8m7-v33v
    - web: https://www.sonarsource.com/blog/diving-into-jumpserver-attackers-gateway-to-internal-networks-2-2
source:
    id: CVE-2024-40629
    created: 2025-03-25T21:01:37.218860374Z
review_status: UNREVIEWED

# for free to join this conversation on GitHub. Already have an account? # to comment
Projects
None yet
Development

No branches or pull requests

2 participants