Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-32147

Опубликовано: 21 апр. 2026
Источник: nvd
CVSS3: 4.3
EPSS Низкий

Описание

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Erlang OTP ssh (ssh_sftpd module) allows an authenticated SFTP user to modify file attributes outside the configured chroot directory.

The SFTP daemon (ssh_sftpd) stores the raw, user-supplied path in file handles instead of the chroot-resolved path. When SSH_FXP_FSETSTAT is issued on such a handle, file attributes (permissions, ownership, timestamps) are modified on the real filesystem path, bypassing the root directory boundary entirely.

Any authenticated SFTP user on a server configured with the root option can modify file attributes of files outside the intended chroot boundary. The prerequisite is that a target file must exist on the real filesystem at the same relative path. Note that this vulnerability only allows modification of file attributes; file contents cannot be read or altered through this attack vector.

If the SSH daemon runs as root, this enables direct privilege escalat

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:*
Версия от 17.0 (включая) до 26.2.5.20 (исключая)
cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:*
Версия от 27.0 (включая) до 27.3.4.11 (исключая)
cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:*
Версия от 28.0 (включая) до 28.4.3 (исключая)
cpe:2.3:a:erlang:erlang\/ssh:*:*:*:*:*:*:*:*
Версия от 3.0.1 (включая) до 5.1.4.15 (исключая)
cpe:2.3:a:erlang:erlang\/ssh:*:*:*:*:*:*:*:*
Версия от 5.2 (включая) до 5.2.11.7 (исключая)
cpe:2.3:a:erlang:erlang\/ssh:*:*:*:*:*:*:*:*
Версия от 5.5 (включая) до 5.5.2 (исключая)

EPSS

Процентиль: 28%
0.00354
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 4.3
ubuntu
4 месяца назад

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Erlang OTP ssh (ssh_sftpd module) allows an authenticated SFTP user to modify file attributes outside the configured chroot directory. The SFTP daemon (ssh_sftpd) stores the raw, user-supplied path in file handles instead of the chroot-resolved path. When SSH_FXP_FSETSTAT is issued on such a handle, file attributes (permissions, ownership, timestamps) are modified on the real filesystem path, bypassing the root directory boundary entirely. Any authenticated SFTP user on a server configured with the root option can modify file attributes of files outside the intended chroot boundary. The prerequisite is that a target file must exist on the real filesystem at the same relative path. Note that this vulnerability only allows modification of file attributes; file contents cannot be read or altered through this attack vector. If the SSH daemon runs as root, this enables direct privilege escalat...

msrc
3 месяца назад

SFTP chroot bypass via path traversal in SSH_FXP_FSETSTAT

CVSS3: 4.3
debian
4 месяца назад

Improper Limitation of a Pathname to a Restricted Directory ('Path Tra ...

suse-cvrf
2 месяца назад

Security update for erlang

suse-cvrf
3 месяца назад

Security update for erlang26

EPSS

Процентиль: 28%
0.00354
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-22