Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS1tam1xLWd3Z20tNXFobc4AA0hU

Apache MINA SSHD information disclosure vulnerability

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache MINA.

In SFTP servers implemented using Apache MINA SSHD that use a RootedFileSystem, logged users may be able to discover "exists/does not exist" information about items outside the rooted tree via paths including parent navigation ("..") beyond the root, or involving symlinks.

This issue affects Apache MINA: from 1.0 before 2.9.3 Users are recommended to upgrade to 2.9.3

Until version 2.1.0, some of the code affected by this vulnerability appeared in org.apache.sshd:sshd-core. Version 2.1.0 contains a commit where the code was moved to the package org.apache.sshd:sshd-common, which did not exist until version 2.1.0.

Permalink: https://github.com/advisories/GHSA-mjmq-gwgm-5qhm
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1tam1xLWd3Z20tNXFobc4AA0hU
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: 10 months ago
Updated: 5 months ago


CVSS Score: 5.0
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

Identifiers: GHSA-mjmq-gwgm-5qhm, CVE-2023-35887
References: Repository: https://github.com/apache/mina-sshd
Blast Radius: 17.0

Affected Packages

maven:org.apache.sshd:sshd-sftp
Dependent packages: 114
Dependent repositories: 338
Downloads:
Affected Version Ranges: >= 1.0.0, < 2.9.3
Fixed in: 2.9.3
All affected versions: 2.0.0, 2.1.0, 2.2.0, 2.3.0, 2.4.0, 2.5.0, 2.5.1, 2.6.0, 2.7.0, 2.8.0, 2.9.0, 2.9.1, 2.9.2
All unaffected versions: 0.9.0, 0.10.0, 0.10.1, 0.11.0, 2.9.3, 2.10.0, 2.11.0, 2.12.0, 2.12.1
maven:org.apache.sshd:sshd-common
Dependent packages: 87
Dependent repositories: 165
Downloads:
Affected Version Ranges: >= 2.1.0, < 2.9.3
Fixed in: 2.9.3
All affected versions: 2.1.0, 2.2.0, 2.3.0, 2.4.0, 2.5.0, 2.5.1, 2.6.0, 2.7.0, 2.8.0, 2.9.0, 2.9.1, 2.9.2
All unaffected versions: 2.9.3, 2.10.0, 2.11.0, 2.12.0, 2.12.1
maven:org.apache.sshd:sshd-core
Dependent packages: 460
Dependent repositories: 2,568
Downloads:
Affected Version Ranges: >= 1.0.0, < 2.1.0
Fixed in: 2.1.0
All affected versions: 1.0.0, 1.1.0, 1.1.1, 1.2.0, 1.3.0, 1.4.0, 1.6.0, 1.7.0, 2.0.0
All unaffected versions: 0.4.0, 0.5.0, 0.6.0, 0.7.0, 0.8.0, 0.9.0, 0.10.0, 0.10.1, 0.11.0, 0.12.0, 0.13.0, 0.14.0, 2.1.0, 2.2.0, 2.3.0, 2.4.0, 2.5.0, 2.5.1, 2.6.0, 2.7.0, 2.8.0, 2.9.0, 2.9.1, 2.9.2, 2.9.3, 2.10.0, 2.11.0, 2.12.0, 2.12.1