CVE-2023-35887

Source
https://nvd.nist.gov/vuln/detail/CVE-2023-35887
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-35887.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-35887
Aliases
Related
Published
2023-07-10T16:15:53Z
Modified
2024-10-12T10:58:34.808757Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache MINA.

In SFTP servers implemented using Apache MINA SSHD that use a RootedFileSystem, logged users may be able to discover "exists/does not exist" information about items outside the rooted tree via paths including parent navigation ("..") beyond the root, or involving symlinks.

This issue affects Apache MINA: from 1.0 before 2.10. Users are recommended to upgrade to 2.10

References

Affected packages

Git / github.com/apache/mina-sshd

Affected ranges

Type
GIT
Repo
https://github.com/apache/mina-sshd
Events

Affected versions

sshd-1.*

sshd-1.0.0
sshd-1.1.0
sshd-1.2.0
sshd-1.3.0
sshd-1.4.0
sshd-1.5.0
sshd-1.6.0
sshd-1.7.0

sshd-2.*

sshd-2.0.0
sshd-2.1.0
sshd-2.2.0
sshd-2.3.0
sshd-2.4.0
sshd-2.5.0
sshd-2.5.1
sshd-2.6.0
sshd-2.7.0
sshd-2.8.0
sshd-2.9.0
sshd-2.9.1
sshd-2.9.2