CVE 7.1 HIGH

JumpServer Unauthorized LDAP Configuration Access via WebSocket_CVE-2025-62795

7.1 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

Description

JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v3.10.21-lts and v4.10.12-lts, a low-privileged authenticated user can invoke LDAP configuration tests and start LDAP synchronization by sending crafted messages to the /ws/ldap/ WebSocket endpoint, bypassing authorization checks and potentially exposing LDAP credentials or causing unintended sync operations. This vulnerability is fixed in v3.10.21-lts and v4.10.12-lts.

Basic Information

ID CVE-2025-62795
Source GitHub_M
Published Oct 30, 2025 at 16:56

Affected Product

Vendor jumpserver
Product jumpserver
Version < 3.10.21-lts
Affected Versions jumpserver jumpserver < 3.10.21-lts
jumpserver jumpserver >= 4.0.0, < 4.10.12-lts

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.