Share
## https://sploitus.com/exploit?id=66F95A30-33DA-5EE7-A450-22DB16D94DE4
# CVE-2023-42820

CVE-2023-42820

## ๆผๆดž่ฏดๆ˜Ž

JumpServer ๅฏ†็ ้‡็ฝฎๆผๆดž

## USAGE

### V2 Update

1. ๅ…จๆ–ฐ้‡ๆž„
2. ๆ–ฐๅขžๆฒกๆœ‰ๆŽฅๆ”ถๅˆฐ่ดฆๆˆทๅ’Œ้‚ฎ็ฎฑ็š„ๆƒ…ๅ†ตไธ‹๏ผŒไฝฟ็”จ้ป˜่ฎค่ดฆๆˆทๅ’Œ้‚ฎ็ฎฑ
3. ๆ”น่ฟ›ๅฏน้ชŒ่ฏ็ ็š„่ฏ†ๅˆซๅ’Œ่ฎก็ฎ—
4. ่‡ชๅŠจไฟฎๆ”นๅฏ†็ 
5. ๅฑ่”ฝๅคšไฝ™็š„logs่พ“ๅ‡บ

![v2](https://raw.githubusercontent.com/C1ph3rX13/CVE-2023-42820/main/image/CVE-2023-42820%20v2.png)

### V1

่ฎก็ฎ—้ชŒ่ฏ็ ้œ€่ฆๆŒ‡ๅฎšๅฏนๅบ”้‚ฎ็ฎฑ็š„็”จๆˆทๅ๏ผŒ่ฟ่กŒๅŽไผš่‡ชๅŠจๅˆคๆ–ญๆ˜ฏๅฆๅญ˜ๅœจๆผๆดž๏ผŒๅนถๅฐ่ฏ•่ฎก็ฎ—้ชŒ่ฏ็ 

~~~python
python CVE-2023-42820.py -t http://IP:Port -e email -u username

 โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ•—โ–ˆโ–ˆโ•—   โ–ˆโ–ˆโ•—โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ•—    โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ•—  โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ•— โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ•— โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ•—       โ–ˆโ–ˆโ•—  โ–ˆโ–ˆโ•—โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ•—  โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ•— โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ•—  โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ•—
โ–ˆโ–ˆโ•”โ•โ•โ•โ•โ•โ–ˆโ–ˆโ•‘   โ–ˆโ–ˆโ•‘โ–ˆโ–ˆโ•”โ•โ•โ•โ•โ•    โ•šโ•โ•โ•โ•โ–ˆโ–ˆโ•—โ–ˆโ–ˆโ•”โ•โ–ˆโ–ˆโ–ˆโ–ˆโ•—โ•šโ•โ•โ•โ•โ–ˆโ–ˆโ•—โ•šโ•โ•โ•โ•โ–ˆโ–ˆโ•—      โ–ˆโ–ˆโ•‘  โ–ˆโ–ˆโ•‘โ•šโ•โ•โ•โ•โ–ˆโ–ˆโ•—โ–ˆโ–ˆโ•”โ•โ•โ–ˆโ–ˆโ•—โ•šโ•โ•โ•โ•โ–ˆโ–ˆโ•—โ–ˆโ–ˆโ•”โ•โ–ˆโ–ˆโ–ˆโ–ˆโ•—
โ–ˆโ–ˆโ•‘     โ–ˆโ–ˆโ•‘   โ–ˆโ–ˆโ•‘โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ•—โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ•— โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ•”โ•โ–ˆโ–ˆโ•‘โ–ˆโ–ˆโ•”โ–ˆโ–ˆโ•‘ โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ•”โ• โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ•”โ•โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ•—โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ•‘ โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ•”โ•โ•šโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ•”โ• โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ•”โ•โ–ˆโ–ˆโ•‘โ–ˆโ–ˆโ•”โ–ˆโ–ˆโ•‘
โ–ˆโ–ˆโ•‘     โ•šโ–ˆโ–ˆโ•— โ–ˆโ–ˆโ•”โ•โ–ˆโ–ˆโ•”โ•โ•โ•โ•šโ•โ•โ•โ•โ•โ–ˆโ–ˆโ•”โ•โ•โ•โ• โ–ˆโ–ˆโ–ˆโ–ˆโ•”โ•โ–ˆโ–ˆโ•‘โ–ˆโ–ˆโ•”โ•โ•โ•โ•  โ•šโ•โ•โ•โ–ˆโ–ˆโ•—โ•šโ•โ•โ•โ•โ•โ•šโ•โ•โ•โ•โ–ˆโ–ˆโ•‘โ–ˆโ–ˆโ•”โ•โ•โ•โ• โ–ˆโ–ˆโ•”โ•โ•โ–ˆโ–ˆโ•—โ–ˆโ–ˆโ•”โ•โ•โ•โ• โ–ˆโ–ˆโ–ˆโ–ˆโ•”โ•โ–ˆโ–ˆโ•‘
โ•šโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ•— โ•šโ–ˆโ–ˆโ–ˆโ–ˆโ•”โ• โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ•—    โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ•—โ•šโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ•”โ•โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ•—โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ•”โ•           โ–ˆโ–ˆโ•‘โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ•—โ•šโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ•”โ•โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ•—โ•šโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ•”โ•
 โ•šโ•โ•โ•โ•โ•โ•  โ•šโ•โ•โ•โ•  โ•šโ•โ•โ•โ•โ•โ•โ•    โ•šโ•โ•โ•โ•โ•โ•โ• โ•šโ•โ•โ•โ•โ•โ• โ•šโ•โ•โ•โ•โ•โ•โ•โ•šโ•โ•โ•โ•โ•โ•            โ•šโ•โ•โ•šโ•โ•โ•โ•โ•โ•โ• โ•šโ•โ•โ•โ•โ• โ•šโ•โ•โ•โ•โ•โ•โ• โ•šโ•โ•โ•โ•โ•โ•
                                                                            @Auth: C1ph3rX13
                                                                            @Blog: https://c1ph3rx13.github.io
                                                                            @Note: ไปฃ็ ไป…ไพ›ๅญฆไน ไฝฟ็”จ๏ผŒ่ฏทๅ‹ฟ็”จไบŽๅ…ถไป–็”จ้€”


usage: CVE-2023-42820.py [-h] -t TARGET -e EMAIL -u USERNAME [--proxy PROXY]

CVE-2023-42820 by C1ph3rX13.

optional arguments:
  -h, --help            show this help message and exit
  -t TARGET, --target TARGET
                        target url
  -e EMAIL, --email EMAIL
                        account email
  -u USERNAME, --username USERNAME
                        account username
  --proxy PROXY         proxy to http://ip:port
~~~

![image-1](https://raw.githubusercontent.com/C1ph3rX13/CVE-2023-42820/main/image/1.png)

![image-2](https://raw.githubusercontent.com/C1ph3rX13/CVE-2023-42820/main/image/2.png)

## ๅ…่ดฃๅฃฐๆ˜Ž

1. ๆœฌๅทฅๅ…ทไป…้ขๅ‘ๆ‹ฅๆœ‰ๅˆๆณ•ๆŽˆๆƒ็š„ๆธ—้€ๆต‹่ฏ•ๅฎ‰ๅ…จไบบๅ‘˜ๅŠ่ฟ›่กŒๅธธ่ง„ๆ“ไฝœ็š„็ฝ‘็ปœ่ฟ็ปดไบบๅ‘˜๏ผŒ็”จๆˆทๅฏๅœจๅ–ๅพ—่ถณๅคŸๅˆๆณ•ๆŽˆๆƒไธ”้žๅ•†็”จ็š„ๅ‰ๆไธ‹่ฟ›่กŒไธ‹่ฝฝใ€ๅคๅˆถใ€ไผ ๆ’ญๆˆ–ไฝฟ็”จใ€‚
2. ๅœจไฝฟ็”จๆœฌๅทฅๅ…ท็š„่ฟ‡็จ‹ไธญ๏ผŒๆ‚จๅบ”็กฎไฟ่‡ชๅทฑ็š„ๆ‰€ๆœ‰่กŒไธบ็ฌฆๅˆๅฝ“ๅœฐๆณ•ๅพ‹ๆณ•่ง„๏ผŒไธ”ไธๅพ—ๅฐ†ๆญค่ฝฏไปถ็”จไบŽ่ฟๅไธญๅ›ฝไบบๆฐ‘ๅ…ฑๅ’Œๅ›ฝ็›ธๅ…ณๆณ•ๅพ‹็š„ๆดปๅŠจใ€‚ๆœฌๅทฅๅ…ทๆ‰€ๆœ‰ไฝœ่€…ๅ’Œ่ดก็Œฎ่€…ไธๆ‰ฟๆ‹…็”จๆˆทๆ“…่‡ชไฝฟ็”จๆœฌๅทฅๅ…ทไปŽไบ‹ไปปไฝ•่ฟๆณ•ๆดปๅŠจๆ‰€ไบง็”Ÿ็š„ไปปไฝ•่ดฃไปปใ€‚

### ๅ‚่€ƒ

https://github.com/vulhub/vulhub/tree/master/base/jumpserver/3.6.3