CVE-2023-35887

Source
https://cve.org/CVERecord?id=CVE-2023-35887
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-35887.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2023-35887
Aliases
Downstream
Related
Published
2023-07-10T09:28:54.987Z
Modified
2026-05-08T04:52:12.337016Z
Severity
  • 5.0 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N CVSS Calculator
Summary
Apache MINA SSHD: Information disclosure bugs with RootedFilesystem
Details

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache MINA.

In SFTP servers implemented using Apache MINA SSHD that use a RootedFileSystem, logged users may be able to discover "exists/does not exist" information about items outside the rooted tree via paths including parent navigation ("..") beyond the root, or involving symlinks.

This issue affects Apache MINA: from 1.0 before 2.10. Users are recommended to upgrade to 2.10

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/35xxx/CVE-2023-35887.json",
    "cwe_ids": [
        "CWE-22"
    ],
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "1.0"
                },
                {
                    "fixed": "2.10"
                }
            ],
            "source": "AFFECTED_FIELD"
        },
        {
            "extracted_events": [
                {
                    "introduced": "1.0"
                },
                {
                    "fixed": "2.10"
                }
            ],
            "source": "DESCRIPTION"
        }
    ],
    "cna_assigner": "apache"
}
References

Affected packages

Git / github.com/apache/mina-sshd

Affected ranges

Type
GIT
Repo
https://github.com/apache/mina-sshd
Events
Database specific
{
    "cpe": "cpe:2.3:a:apache:sshd:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "1.0.0"
        },
        {
            "fixed": "2.9.3"
        }
    ],
    "source": "CPE_FIELD"
}

Affected versions

sshd-1.*
sshd-1.0.0
sshd-1.1.0
sshd-1.2.0
sshd-1.3.0
sshd-1.4.0
sshd-1.5.0
sshd-1.6.0
sshd-1.7.0
sshd-2.*
sshd-2.0.0
sshd-2.1.0
sshd-2.2.0
sshd-2.3.0
sshd-2.4.0
sshd-2.5.0
sshd-2.5.1
sshd-2.6.0
sshd-2.7.0
sshd-2.8.0
sshd-2.9.0
sshd-2.9.1
sshd-2.9.2

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-35887.json"