Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
blackjump — JumpServer 堡垒机未授权综合漏洞利用, Exploit for CVE-2023-42442 / CVE-2023-42820 / RCE 2021 | Kitploit
Tools/GitHubGitHub/tarihub/blackjump
Vulnerability AnalysisExploitationWeb Application ExploitationInformation GatheringPenetration TestingCommand and Control
GitHubtarihub/blackjump

blackjump

JumpServer 堡垒机未授权综合漏洞利用, Exploit for CVE-2023-42442 / CVE-2023-42820 / RCE 2021

View Repository
27631141 year agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

blackjump

简体中文 | English

Legal Disclaimer: This tool is only intended for legally authorized enterprise security construction activities.

When using this tool for testing, you should ensure that the behavior complies with local laws and regulations and has obtained sufficient authorization. Do not use against unauthorized targets.

If you engage in any illegal behavior during the use of this tool, you shall bear the corresponding consequences on your own, and we will not assume any legal or joint liability

JumpServer Fortress Machine Integrated Vulnerability Exploit Tool

  • Unauthorized password reset for any user (CVE-2023-42820)
  • Unauthorized download of all operation videos (CVE-2023-42442)
  • Unauthorized Remote Command Execution (RCE 2021)

Install

python3 -m pip install -r requirements.txt

Usage

  • CVE-2023-42820: You can specify --user and --email option if you know the username and email in reset password module
python3 blackjump.py reset https://vulerability

img.png

  • CVE-2023-42442: The <uuid4>.tar file in the outputs/ directory can be thrown into the jumpserver player
python3 blackjump.py dump https://vulerability

img_1.png

  • RCE
python3 blackjump.py rce http(s)://vulerability

img.png

  • help
python3 blackjump.py {reset,dump,rce} -h

Ref

  1. https://github.com/Veraxy00/Jumpserver-EXP (Made some optimizations)
Download Tool