CVE-2024-29202

CVSS 3.1 Score 9.9 of 10 (high)

Details

Published Mar 29, 2024
Updated: Jan 9, 2025
CWE ID 94

Summary

CVE-2024-29202 is a Jinja2 template injection vulnerability affecting JumpServer, an open-source bastion host and auditing system. The flaw is located in JumpServer's Ansible component, which can be exploited by attackers to inject and execute arbitrary code within the Celery container. Since the Celery container runs with root privileges and has database access, successful exploitation could result in the theft of sensitive information or manipulation of the database for all connected hosts. This vulnerability is resolved in version 3.10.7.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Fit2cloud Jumpserver

Affected Vendors

  • FIT2CLOUD