CVE-2025-62795: FIT2CLOUD Jumpserver
High severity, CVSS 7.1. EPSS: 0.3% chance of exploitation in the next 30 days.
JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v3.10.21-lts and v4.10.12-lts, a low-privileged authenticated user can invoke LDAP configuration tests and start LDAP synchronization by sending crafted messages to the /ws/ldap/ WebSocket endpoint, bypassing authorization checks and potentially exposing LDAP credentials or causing unintended sync operations. This vulnerability is fixed in v3.10.21-lts and v4.10.12-lts.
Affected products
- FIT2CLOUD Jumpserver: before 3.10.21 (fixed in 3.10.21); from 4.0.0, before 4.10.12 (fixed in 4.10.12)
Published 2025-10-30. Last modified 2026-06-17.