CVE-2023-48193: FIT2CLOUD Jumpserver
Critical severity, CVSS 9.8. EPSS: 2% chance of exploitation in the next 30 days.
Insecure Permissions vulnerability in JumpServer GPLv3 v.3.8.0 allows a remote attacker to execute arbitrary code via bypassing the command filtering function. NOTE: this is disputed because command filtering is not intended to restrict what code can be run by authorized users who are allowed to execute files.
Affected products
- FIT2CLOUD Jumpserver: version 3.8.0 only
Published 2023-11-28. Last modified 2026-07-09.