CVE Database
/

CVE-2025-58044

Back to search

CVE-2025-58044

Published: Dec 1, 2025

Modified: Dec 1, 2025

PUBLISHED

Description

JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v3.10.19 and v4.10.5, The /core/i18n// endpoint uses the Referer header as the redirection target without proper validation, which could lead to an Open Redirect vulnerability. This vulnerability is fixed in v3.10.19 and v4.10.5.

VendorProductVersions

jumpserver

jumpserver

affected
< 3.10.19
affected
>= 4.0.0, < 4.10.5

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now