#VU128124 Improper access control in JumpServer - CVE-2024-40629
Published: July 18, 2024 / Updated: April 27, 2026
JumpServer
JumpServer
Description
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper access control in the Ansible playbook feature when creating and running playbook templates through the Job Center. A remote user can write arbitrary files in the Celery container to execute arbitrary code.
Exploitation requires access to at least one host and access to the Job Center feature. The Celery container runs as root and has database access.