Vulnerabilities > Fit2Cloud

DATE CVE VULNERABILITY TITLE RISK
2024-07-18 CVE-2024-40628 Path Traversal vulnerability in Fit2Cloud Jumpserver
JumpServer is an open-source Privileged Access Management (PAM) tool that provides DevOps and IT teams with on-demand and secure access to SSH, RDP, Kubernetes, Database and RemoteApp endpoints through a web browser.
network
low complexity
fit2cloud CWE-22
critical
9.1
2024-07-18 CVE-2024-40629 Path Traversal vulnerability in Fit2Cloud Jumpserver
JumpServer is an open-source Privileged Access Management (PAM) tool that provides DevOps and IT teams with on-demand and secure access to SSH, RDP, Kubernetes, Database and RemoteApp endpoints through a web browser.
network
low complexity
fit2cloud CWE-22
critical
9.8
2024-07-18 CVE-2024-39907 SQL Injection vulnerability in Fit2Cloud 1Panel 1.10.10Lts/1.10.9Lts
1Panel is a web-based linux server management control panel.
network
low complexity
fit2cloud CWE-89
critical
9.8
2024-07-18 CVE-2024-39911 SQL Injection vulnerability in Fit2Cloud 1Panel 1.10.10Lts
1Panel is a web-based linux server management control panel.
network
low complexity
fit2cloud CWE-89
critical
9.8
2024-02-05 CVE-2024-24768 Missing Encryption of Sensitive Data vulnerability in Fit2Cloud 1Panel 1.9.5
1Panel is an open source Linux server operation and maintenance management panel.
network
low complexity
fit2cloud CWE-311
7.5
2024-01-06 CVE-2023-50612 Incorrect Default Permissions vulnerability in Fit2Cloud Cloudexplorer Lite 1.4.1
Insecure Permissions vulnerability in fit2cloud Cloud Explorer Lite version 1.4.1, allow local attackers to escalate privileges and obtain sensitive information via the cloud accounts parameter.
local
low complexity
fit2cloud CWE-276
7.8
2023-11-28 CVE-2023-48193 Unspecified vulnerability in Fit2Cloud Jumpserver 3.8.0
Insecure Permissions vulnerability in JumpServer GPLv3 v.3.8.0 allows a remote attacker to execute arbitrary code via bypassing the command filtering function.
network
low complexity
fit2cloud
critical
9.8
2023-10-31 CVE-2023-46138 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Fit2Cloud Jumpserver
JumpServer is an open source bastion host and maintenance security audit system that complies with 4A specifications.
network
low complexity
fit2cloud CWE-640
5.3
2023-10-30 CVE-2023-44397 Improper Authentication vulnerability in Fit2Cloud Cloudexplorer Lite
CloudExplorer Lite is an open source, lightweight cloud management platform.
network
low complexity
fit2cloud CWE-287
critical
9.8
2023-10-25 CVE-2023-46123 Improper Restriction of Excessive Authentication Attempts vulnerability in Fit2Cloud Jumpserver
jumpserver is an open source bastion machine, professional operation and maintenance security audit system that complies with 4A specifications.
network
low complexity
fit2cloud CWE-307
5.3