CVE-2023-42820
Random seed leakage in Jumpserver
- Published
- Sep 26, 2023
- Updated
- Sep 23, 2024
- Assigning CNA
- GitHub_M
- Evidence observed
- Aug 24, 2026
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:NLow · next 30 days
- Percentile
- 92.4%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
JumpServer is an open source bastion host. This vulnerability is due to exposing the random number seed to the API, potentially allowing the randomly generated verification codes to be replayed, which could lead to password resets. If MFA is enabled users are not affect. Users not using local authentication are also not affected. Users are advised to upgrade to either version 2.28.19 or to 3.6.5. There are no known workarounds or this issue.
Sources
4- CVE-2023-42820Exploit
Exploit script for JumpServer password reset vulnerability CVE-2023-42820, with automatic verification code calculation and password modification.
- cve-2023-42820Exploit
JumpServer
- blackjumpExploit
JumpServer Bastion Host Unauthorized Comprehensive Vulnerability Exploitation, Exploit for CVE-2023-42442 / CVE-2023-42820 / RCE 2021
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.