An issue in Jumpserver before 2.6.2, before 2.5.4, before 2.4.5 allows attackers to create a connection token through an API which does not have access control and use it to access sensitive assets.
| Software | From | Fixed in |
|---|---|---|
| jumpserver / jumpserver | 2.4.0 | 2.4.5 |
| jumpserver / jumpserver | 2.5.0 | 2.5.4 |
| jumpserver / jumpserver | 2.6.0 | 2.6.2 |