Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2023-42442 — CVE-2023-42442 JumpServer Session 录像任意下载漏洞 | Kitploit
Tools/GitHubGitHub/c1ph3rx13/cve-2023-42442
Vulnerability AnalysisExploitationWeb Application ExploitationAPI Security TestingInformation GatheringPenetration Testing
GitHubc1ph3rx13/cve-2023-42442

CVE-2023-42442

CVE-2023-42442 JumpServer Session 录像任意下载漏洞

View Repository
9132 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2023-42442

CVE-2023-42442 JumpServer Session Recording Arbitrary Download Vulnerability

Vulnerability Description

CVE-2023-42442 is a combination vulnerability involving two bugs in Jumpserver

  1. Unauthorized API access leading to session information disclosure

  2. Directory permission bypass allowing recording files to be downloaded

USAGE

Python Version

python CVE-2023-42442.py -h


     ██████╗██╗   ██╗███████╗    ██████╗  ██████╗ ██████╗ ██████╗       ██╗  ██╗██████╗ ██╗  ██╗██╗  ██╗██████╗
    ██╔════╝██║   ██║██╔════╝    ╚════██╗██╔═████╗╚════██╗╚════██╗      ██║  ██║╚════██╗██║  ██║██║  ██║╚════██╗
    ██║     ██║   ██║█████╗█████╗ █████╔╝██║██╔██║ █████╔╝ █████╔╝█████╗███████║ █████╔╝███████║███████║ █████╔╝
    ██║     ╚██╗ ██╔╝██╔══╝╚════╝██╔═══╝ ████╔╝██║██╔═══╝  ╚═══██╗╚════╝╚════██║██╔═══╝ ╚════██║╚════██║██╔═══╝
    ╚██████╗ ╚████╔╝ ███████╗    ███████╗╚██████╔╝███████╗██████╔╝           ██║███████╗     ██║     ██║███████╗
     ╚═════╝  ╚═══╝  ╚══════╝    ╚══════╝ ╚═════╝ ╚══════╝╚═════╝            ╚═╝╚══════╝     ╚═╝     ╚═╝╚══════╝

        @Auth: C1ph3rX13
        @Blog: https://c1ph3rx13.github.io
        @Note: Code is for learning purposes only, do not use for other purposes


usage: CVE-2023-42442.py [-h] -t TARGET

CVE-2023-42442 by C1ph3rX13.

options:
  -h, --help            show this help message and exit
  -t TARGET, --target TARGET
                        target url

image-1

Go Version

Build

# Source code compilation, currently only supports Windows
go mod init CVE-2023-42442
go mod tidy
go build -ldflags="-s -w" -trimpath -o CVE-2023-42442.exe .\CVE-2023-42442.go

Run

.\CVE-2023-42442.exe -h


        ██████╗██╗   ██╗███████╗    ██████╗  ██████╗ ██████╗ ██████╗       ██╗  ██╗██████╗ ██╗  ██╗██╗  ██╗██████╗
        ██╔════╝██║   ██║██╔════╝    ╚════██╗██╔═████╗╚════██╗╚════██╗      ██║  ██║╚════██╗██║  ██║██║  ██║╚════██╗
        ██║     ██║   ██║█████╗█████╗ █████╔╝██║██╔██║ █████╔╝ █████╔╝█████╗███████║ █████╔╝███████║███████║ █████╔╝
        ██║     ╚██╗ ██╔╝██╔══╝╚════╝██╔═══╝ ████╔╝██║██╔═══╝  ╚═══██╗╚════╝╚════██║██╔═══╝ ╚════██║╚════██║██╔═══╝
        ╚██████╗ ╚████╔╝ ███████╗    ███████╗╚██████╔╝███████╗██████╔╝           ██║███████╗     ██║     ██║███████╗
        ╚═════╝  ╚═══╝  ╚══════╝    ╚══════╝ ╚═════╝ ╚══════╝╚═════╝            ╚═╝╚══════╝     ╚═╝     ╚═╝╚══════╝

        @Auth: C1ph3rX13
        @Blog: https://c1ph3rx13.github.io
        @Note: Code is for learning purposes only, do not use for other purposes

Usage of CVE-2023-42442.exe:
  -proxy string
        Proxy Url: http/https://IP:Port
  -t string
        Target Url

img

Changelog

  • 2023-10-31 Optimized Go Version, reduced code size

Issues

  • httpx automatically normalizes the input url format, even when using Writing custom transports

  • httpx wiki: https://www.python-httpx.org/advanced/#writing-custom-transports

  • requests does not

References

Some code references the following projects:

https://github.com/tarimoe/blackjump

Disclaimer

  1. This tool is intended only for penetration testers with legal authorization and network operation personnel performing routine operations. Users may download, copy, distribute, or use it only after obtaining sufficient legal authorization and for non-commercial purposes.
  2. When using this tool, you must ensure that all your actions comply with local laws and regulations, and must not use this software for activities that violate the relevant laws of the People's Republic of China. All authors and contributors of this tool assume no responsibility for any illegal activities resulting from unauthorized use of this tool.
Download Tool