CVE-2024-29202
CVSS 3.1 Score 9.9 of 10 (high)
Details
Published Mar 29, 2024
Updated: Apr 1, 2024
CWE ID 94
Summary
CVE-2024-29202 is a Jinja2 template injection vulnerability affecting the open-source bastion host and operation maintenance security audit system, JumpServer. The flaw exists in JumpServer's Ansible component and can allow attackers to execute arbitrary code within the Celery container. Since the Celery container runs with root privileges and has database access, successful exploitation could result in the theft of sensitive information from all hosts or manipulation of the database. This vulnerability has been addressed in JumpServer version 3.10.7.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share