CVE-2025-58044 MEDIUM

CVE-2025-58044: JumpServer has an Open Redirect Vulnerability

Vendor Jumpserver
Product jumpserver
Weakness CWE-601 · Open redirect
Published December 1, 2025
Last update December 1, 2025

CVSS base score

5.5/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:L/E:P

What the vulnerability does

01Description

JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v3.10.19 and v4.10.5, The /core/i18n// endpoint uses the Referer header as the redirection target without proper validation, which could lead to an Open Redirect vulnerability. This vulnerability is fixed in v3.10.19 and v4.10.5.

Key dates

02Disclosure timeline

December 1, 2025 CVE published
December 1, 2025 Record updated