Use of Less Trusted Source in JumpServer - CVE-2023-46123
Published: October 24, 2023 / Updated: April 27, 2026
JumpServer
JumpServer
Description
The vulnerability allows a remote attacker to bypass password brute-force protections and disclose sensitive information.
The vulnerability exists due to use of a less trusted source in the Core API authentication endpoint when handling authentication requests that supply client IP address values. A remote attacker can send specially crafted requests with spoofed X-Forwarded-For or remote_addr values to bypass password brute-force protections and disclose sensitive information.