Authorization bypass through user-controlled key in JumpServer - CVE-2024-29024
Published: March 29, 2024 / Updated: April 27, 2026
JumpServer
JumpServer
Description
The vulnerability allows a remote user to upload malicious files.
The vulnerability exists due to improper access control in the file manager bulk transfer functionality when handling file upload jobs by job ID. A remote user can manipulate a job ID in a specially crafted POST request to upload malicious files.
User interaction is required because a legitimate user must first initiate a file upload operation that generates a job ID.