Skip to content

Default admin user email leak to password reset

Low
ibuler published GHSA-9mrc-75cv-46cq Oct 26, 2023

Package

jumpserver

Affected versions

<3.8.0

Patched versions

>=3.8.0

Description

Impact

The default email for initial user admin is admin@mycompany.com, and users reset their passwords by sending an email. Currently, the domain mycompany.com has not been registered. However, if it is registered in the future, it may affect the password reset functionality.

So should change default domain to example.com, which is reserved

Patches

>= v3.8.0

Workarounds

If you don't want to upgrade, you can fix it by changing the default email of admin

References

Thanks for zhiniang peng(@edwardzpeng) & lawliet with Sangfor report this bug

Severity

Low
3.7
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
High
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
Low
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

CVE ID

CVE-2023-46138

Weaknesses

No CWEs

Credits