Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-35887

Опубликовано: 10 июл. 2023
Источник: redhat
CVSS3: 4.3

Описание

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache MINA. In SFTP servers implemented using Apache MINA SSHD that use a RootedFileSystem, logged users may be able to discover "exists/does not exist" information about items outside the rooted tree via paths including parent navigation ("..") beyond the root, or involving symlinks. This issue affects Apache MINA: from 1.0 before 2.10. Users are recommended to upgrade to 2.10

A flaw was found in Apache Mina SSHD that could be exploited on certain SFTP servers implemented using the Apache Mina RootedFileSystem. This issue could permit authenticated users to view information outside of their permissions scope.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Developer Tools and Servicessshd-commonOut of support scope
OpenShift Serverlesssshd-commonWill not fix
Red Hat Fuse 7sshd-commonOut of support scope
Red Hat Integration Camel Quarkus 2sshd-commonAffected
Red Hat OpenShift Container Platform 3.11sshd-commonOut of support scope
Red Hat OpenShift Container Platform 4sshd-commonOut of support scope
Red Hat Process Automation 7sshd-commonOut of support scope
Red Hat Single Sign-On 7sshd-commonWill not fix
Red Hat support for Spring Bootsshd-commonNot affected
Red Hat Virtualization 4sshd-commonOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2240036apache-mina-sshd: information exposure in SFTP server implementations

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5
nvd
больше 2 лет назад

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache MINA. In SFTP servers implemented using Apache MINA SSHD that use a RootedFileSystem, logged users may be able to discover "exists/does not exist" information about items outside the rooted tree via paths including parent navigation ("..") beyond the root, or involving symlinks. This issue affects Apache MINA: from 1.0 before 2.10. Users are recommended to upgrade to 2.10

CVSS3: 5
debian
больше 2 лет назад

Exposure of Sensitive Information to an Unauthorized Actor vulnerabili ...

CVSS3: 5
github
больше 2 лет назад

Apache MINA SSHD information disclosure vulnerability

CVSS3: 5
fstec
больше 2 лет назад

Уязвимость java-библиотеки для поддержки SSH-протоколов Apache SSHD, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

4.3 Medium

CVSS3