JumpServer Connection Token Improper Authentication Vulnerability (CVE-2025-62712) Notice

JumpServer Connection Token Improper Authentication Vulnerability (CVE-2025-62712) Notice

Overview Recently, NSFOCUS CERT detected that JumpServer issued a security bulletin to fix the JumpServer connection token improper authentication vulnerability (CVE-2025-62712); Due to improper authentication of JumpServer’s /api/v1/authentication/super-connection-token/hyper-connected endpoint, attackers with low-privilege ...

JumpServer Remote Code Execution Vulnerability (CVE-2024-29201/CVE-2024-29202) Notice

Overview Recently, NSFOCUS CERT detected that JumpServer issued a security announcement and fixed two remote code execution vulnerabilities. At present, the PoC of the vulnerability has been made public. Affected users should ...