Описание
Directory traversal vulnerability in JCraft JSch before 0.1.54 on Windows, when the mode is ChannelSftp.OVERWRITE, allows remote SFTP servers to write to arbitrary files via a ..\ (dot dot backslash) in a response to a recursive GET command.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | only affects Windows platforms |
| esm-apps/xenial | not-affected | only affects Windows platforms |
| esm-infra-legacy/trusty | not-affected | only affects Windows platforms |
| precise | not-affected | only affects Windows platforms |
| trusty | not-affected | only affects Windows platforms |
| trusty/esm | not-affected | only affects Windows platforms |
| upstream | released | 0.1.54-1 |
| vivid/stable-phone-overlay | DNE | |
| vivid/ubuntu-core | DNE | |
| xenial | not-affected | only affects Windows platforms |
Показывать по
EPSS
4.3 Medium
CVSS2
5.9 Medium
CVSS3
Связанные уязвимости
Directory traversal vulnerability in JCraft JSch before 0.1.54 on Windows, when the mode is ChannelSftp.OVERWRITE, allows remote SFTP servers to write to arbitrary files via a ..\ (dot dot backslash) in a response to a recursive GET command.
Directory traversal vulnerability in JCraft JSch before 0.1.54 on Windows, when the mode is ChannelSftp.OVERWRITE, allows remote SFTP servers to write to arbitrary files via a ..\ (dot dot backslash) in a response to a recursive GET command.
Directory traversal vulnerability in JCraft JSch before 0.1.54 on Wind ...
Improper Limitation of a Pathname to a Restricted Directory in JCraft JSch
Уязвимость компонента ChannelSftp.OVERWRITE Java-реализации SSH2 jsch, позволяющая нарушителю оказать воздействие на целостность информации
EPSS
4.3 Medium
CVSS2
5.9 Medium
CVSS3