PT-2023-7055 · Apache · Apache Mina

Andrew Pikler

·

Publicado

2023-07-10

·

Atualizado

2024-01-19

·

CVE-2023-35887

CVSS v3.1

5.0

Média

VetorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache MINA versions 1.0 through 2.9.3
Description The issue is related to the exposure of sensitive information to unauthorized actors in Apache MINA SSHD SFTP servers that use a RootedFileSystem. Logged users may be able to discover "exists/does not exist" information about items outside the rooted tree via paths including parent navigation ("..") beyond the root, or involving symlinks.
Recommendations For Apache MINA versions 1.0 through 2.9.3, upgrade to version 2.10 to resolve the issue. As a temporary workaround, consider restricting access to the RootedFileSystem to minimize the risk of exploitation.

Correção

Path traversal

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-08077
CVE-2023-35887
GHSA-MJMQ-GWGM-5QHM
OESA-2024-1079
RHSA-2023:7637
RHSA-2023:7638
RHSA-2023:7639
RHSA-2024:1192
RHSA-2024:1193

Produtos afetados

Apache Mina