Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-45047

Опубликовано: 16 нояб. 2022
Источник: redhat
CVSS3: 9.8
EPSS Низкий

Описание

Class org.apache.sshd.server.keyprovider.SimpleGeneratorHostKeyProvider in Apache MINA SSHD <= 2.9.1 uses Java deserialization to load a serialized java.security.PrivateKey. The class is one of several implementations that an implementor using Apache MINA SSHD can choose for loading the host keys of an SSH server.

A flaw was found in Apache MINA SSHD, when using Java deserialization to load a serialized java.security.PrivateKey. An attacker could benefit from unsafe deserialization by inserting unsecured data that may affect the application or server.

Отчет

Red Hat Impact as High as there's a mitigation for minimizing the impact which the flaw requires org.apache.sshd.server.keyprovider.SimpleGeneratorHostKeyProvider to be impacted, which would require an external/public API for an attacker to benefit from it. Red Hat Fuse 7 and Red Hat JBoss Enterprise Application Platform 7 have a lower rate (moderate) as it's very unlikely to be exploited since those are for internal usage or use a custom implementation in their case.

Меры по смягчению последствий

From the maintainer: For Apache MINA SSHD <= 2.9.1, do not use org.apache.sshd.server.keyprovider.SimpleGeneratorHostKeyProvider to generate and later load your server's host key. Use separately generated host key files, for instance in OpenSSH format, and load them via a org.apache.sshd.common.keyprovider.FileKeyPairProvider instead. Or use a custom implementation instead of SimpleGeneratorHostKeyProvider that uses the OpenSSH format for storing and loading the host key (via classes OpenSSHKeyPairResourceWriter and OpenSSHKeyPairResourceParser).

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Migration Toolkit for Applications 6mina-sshdAffected
Migration Toolkit for Runtimesmina-sshdAffected
Red Hat AMQ Broker 7sshd-commonNot affected
Red Hat build of Apache Camel for Spring Boot 3sshd-commonNot affected
Red Hat Fuse 7sshd-commonAffected
Red Hat Integration Camel K 1sshd-commonNot affected
Red Hat Integration Camel Quarkus 1sshd-commonAffected
Red Hat JBoss Data Grid 7mina-sshdOut of support scope
Red Hat JBoss Enterprise Application Platform 6keycloak-adapter-sso7_5-eap6Out of support scope
Red Hat JBoss Enterprise Application Platform 6sshd-commonOut of support scope

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-502
https://bugzilla.redhat.com/show_bug.cgi?id=2145194mina-sshd: Java unsafe deserialization vulnerability

EPSS

Процентиль: 90%
0.05071
Низкий

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
около 3 лет назад

Class org.apache.sshd.server.keyprovider.SimpleGeneratorHostKeyProvider in Apache MINA SSHD <= 2.9.1 uses Java deserialization to load a serialized java.security.PrivateKey. The class is one of several implementations that an implementor using Apache MINA SSHD can choose for loading the host keys of an SSH server.

CVSS3: 9.8
debian
около 3 лет назад

Class org.apache.sshd.server.keyprovider.SimpleGeneratorHostKeyProvide ...

CVSS3: 9.8
github
около 3 лет назад

Unsafe deserialization in Apache MINA SSHD

CVSS3: 9.8
fstec
около 3 лет назад

Уязвимость класса org.apache.sshd.server.keyprovider.SimpleGeneratorHostKeyProvider java-библиотеки для поддержки SSH-протоколов Apache SSHD, позволяющая нарушителю выполнить произвольный код

suse-cvrf
около 2 лет назад

Security update for apache-parent, apache-sshd

EPSS

Процентиль: 90%
0.05071
Низкий

9.8 Critical

CVSS3