Impact
JumpServer versions prior to 4.10.17 allow an authenticated administrator with Applet Host deployment permissions to inject Jinja2 expressions into the IP/Host or Core Service Address fields. When a host is deployed, Ansible evaluates these expressions as part of its inventory data or playbook variables, enabling arbitrary command execution on the JumpServer control node. The vulnerability is a form of unsafe method execution (CWE-1336) that can compromise the entire bastion host system.
Affected Systems
All installations of JumpServer older than release 4.10.17 are affected. The vendor, JumpServer, provides a fix in version 4.10.17, so any system running JumpServer before this release requires remediation.
Risk and Exploitability
The CVSS score is 6.7, indicating moderate severity. The EPSS score is not available, and the issue is not listed in CISA KEV. Exploitation requires authenticated administrative access with Applet Host management and deployment rights, so the attack vector is remote but limited to privileged users. Once the privilege is obtained, the attacker can execute arbitrary commands on the control node, potentially gaining full system compromise.
OpenCVE Enrichment