In JumpServer, an open source bastion host, the random number seed used for generating verification codes is exposed via the API. This exposure allows an attacker to predict or replay verification codes, potentially enabling unauthorized password resets. The vulnerability affects users relying on local authentication without MFA.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a Python-based exploit tool ('blackjump.py') targeting multiple vulnerabilities in JumpServer, a bastion host management platform. The tool supports three main exploit modules: (1) CVE-2023-42820, which allows unauthorized password reset for any user if the username and email are known; (2) CVE-2023-42442, which enables unauthorized download of all operation video recordings from the server; and (3) an RCE module (2021) that allows remote command execution without authentication. The tool is operated via command-line arguments, specifying the exploit module and the target JumpServer URL. The code interacts with specific JumpServer HTTP endpoints to perform the exploits, and outputs results such as new passwords or downloaded files. The repository contains a single main code file, a requirements file for dependencies, and documentation in both Chinese and English. The exploit is operational and provides real attack capabilities against vulnerable JumpServer instances.
This repository contains two Python exploit scripts (CVE-2023-42820.py and CVE-2023-42820 v2.py) targeting CVE-2023-42820, a password reset vulnerability in JumpServer. The exploit automates the process of resetting a user's password by manipulating the password reset workflow, including CAPTCHA seed prediction and token handling. The scripts use HTTP requests to interact with the target JumpServer instance, parse HTML to extract tokens, and bypass CAPTCHA protections using deterministic random seed logic. The v2 script adds improvements such as default account usage, better CAPTCHA handling, and automatic password change. Both scripts require the target URL and user credentials (with defaults for admin) and can use a proxy if specified. The repository also includes a README with usage instructions and a LICENSE file. The main attack vector is network-based, exploiting exposed HTTP endpoints related to password reset and CAPTCHA. The exploit is operational, providing a working method to reset user passwords on vulnerable JumpServer instances.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.