Jumpserver

Vendor:

First CVE: Mar 16, 2023 · Active for 3 years

24
Total CVEs
More Total CVEs than 95% of tracked products
6.0
Avg CVEs / Year
Higher CVE frequency than 90% of tracked products
7.6
Avg CVSS
Higher Avg CVSS than 60% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Jumpserver over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 16, 2023
3 years ago
Most Recent CVE
Mar 13, 2026
133 days ago

CVE Severity & Scoring

Jumpserver24 CVEs
All CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network24 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (83.3%)
High4 (16.7%)
Unknown0 (0.0%)
User Interaction
None20 (83.3%)
Unknown0 (0.0%)
Required4 (16.7%)
Privileges Required
Low10 (41.7%)
High1 (4.2%)
None13 (54.2%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (24 CVEs).

24 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
JumpServer is an open source bastion host and a professional operation and maintenance security audit system. Starting in version 3.0.0 and prior to versions 3.5.5 and 3.6.4, sessi
Sep 15, 20235.352NOYES
JumpServer is an open source bastion host and an operation and maintenance security audit system. Attackers can exploit a Jinja2 template injection vulnerability in JumpServer's An
Mar 29, 20249.934NONO
JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v3.10.19 and v4.10.5, The /core/i18n// endpoint uses the Referer header a
Dec 1, 20256.133NOYES
JumpServer is an open source bastion host and an operation and maintenance security audit system. Attackers can bypass the input validation mechanism in JumpServer's Ansible to exe
Mar 29, 20249.933NONO
JumpServer is an open source bastion host. An authenticated user can exploit a vulnerability in MongoDB sessions to execute arbitrary commands, leading to remote code execution. Th
Sep 27, 20239.931NONO
JumpServer is an open-source Privileged Access Management (PAM) tool that provides DevOps and IT teams with on-demand and secure access to SSH, RDP, Kubernetes, Database and Remote
Jul 18, 20249.830NONO
Jumpserver is a popular open source bastion host, and Koko is a Jumpserver component that is the Go version of coco, refactoring coco's SSH/SFTP service and Web Terminal service. P
Mar 16, 20239.929NONO
JumpServer is an open source bastion host and an operation and maintenance security audit system. In JumpServer versions prior to v3.10.20-lts and v4.10.11-lts, an authenticated, n
Oct 30, 20258.128NONO
JumpServer is an open-source Privileged Access Management (PAM) tool that provides DevOps and IT teams with on-demand and secure access to SSH, RDP, Kubernetes, Database and Remote
Jul 18, 20249.128NONO
JumpServer is an open source bastion host. As an unauthenticated user, it is possible to authenticate to the core API with a username and an SSH public key without needing a passwo
Sep 27, 20239.128NONO

Exploit Exposure

Signals from CVEs in this product scope (24 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
3 CVEs
12.5% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (24 CVEs).

Media Mentions

Signals from CVEs in this product scope (24 CVEs).

Top CNAs Publishing CVEs For Jumpserver

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.8.019.82.0%00