Improper Restriction of Excessive Authentication Attempts in JumpServer - CVE-2023-43650
Published: September 27, 2023 / Updated: April 27, 2026
JumpServer
JumpServer
Description
The vulnerability allows a remote attacker to take over accounts.
The vulnerability exists due to improper restriction of excessive authentication attempts in the password reset verification code mechanism when validating password reset codes. A remote attacker can brute-force a 6-digit verification code to take over accounts.
The issue affects password reset flows for users who do not use multi-factor authentication, and the verification code is valid for 1 minute.