CVE-2024-29202
CVSS 3.1 Score 9.9 of 10 (high)
Details
Published Mar 29, 2024
Updated: Jan 9, 2025
CWE ID 94
Summary
CVE-2024-29202 is a Jinja2 template injection vulnerability affecting JumpServer, an open-source bastion host and auditing system. The flaw is located in JumpServer's Ansible component, which can be exploited by attackers to inject and execute arbitrary code within the Celery container. Since the Celery container runs with root privileges and has database access, successful exploitation could result in the theft of sensitive information or manipulation of the database for all connected hosts. This vulnerability is resolved in version 3.10.7.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Fit2cloud Jumpserver
Affected Vendors
- FIT2CLOUD