News

Urgent Security Vulnerability Notification for JumpServer - 20251028

Urgent Security Vulnerability Notification for JumpServer - 20251028

We have recently received user feedback and have confirmed that there is a security vulnerability in JumpServer related to connection tokens. This vulnerability may permit unauthorized access to assets and LDAP servers. We are notifying you of this issue and providing details about the affected versions, patched versions, and recommended emergency actions to help you investigate and mitigate the issue as soon as possible.

Affected versions:

JumpServer V4: <= v4.10.11 LTS

Secure versions:

JumpServer V4: >= v4.10.12 LTS

Remediation:

Upgrade JumpServer to the following secure versions as soon as possible:

JumpServer v4: Upgrade to version >= v4.10.12-lts

You can follow the instructions in the following link to upgrade JumpServer: https://www.jumpserver.com/docs/upgrade#upgrade-for-offline-installation

We highly recommend performing the upgrade to ensure comprehensive protection against this vulnerability.

Thank you for your prompt attention to this matter. If you have any questions or need further assistance, please do not hesitate to contact us.

Keep Reading

Recommended Reading

Important Notice: JumpServer Vulnerability Advisory and Remediation (JS-2026.09.09)
Security

Important Notice: JumpServer Vulnerability Advisory and Remediation (JS-2026.09.09)

JumpServer security advisory JS-2026.09.09: an improper API filtering vulnerability (GHSA-6rp5-ff2m-qfrm, High, CVSS 8.8) lets any authenticated user retrieve administrator Access Keys by appending a query parameter. Affects V3 >= v3.7.0 and < v3.10.23 LTS, and V4 >= v4.0.0 and < v4.10.19 LTS. Upgrade or apply the Nginx workaround immediately.

Download Community Free Trial