CVE-2023-42818
SSH public key login without private key challenge if mfa is enabled in jumpserver in github.com/jumpserver/koko in github.com/jumpserver/jumpserver
EPSS 0.17%
Description
SSH public key login without private key challenge if mfa is enabled in jumpserver in github.com/jumpserver/koko in github.com/jumpserver/jumpserver
How to fix CVE-2023-42818
To remediate CVE-2023-42818, upgrade the affected package to a fixed version below.
- Go/github.com/jumpserver/jumpserver—upgrade to 3.5.6+incompatible or later
- Go/github.com/jumpserver/koko—no fix listed
Is CVE-2023-42818 being exploited?
Low — EPSS is 0.2%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 3.5.6+incompatible, >= 3.6.0+incompatible, < 3.6.5+incompatible
- from 0