PT-2023-7055 · Apache · Apache Mina
Andrew Pikler
·
Publicado
2023-07-10
·
Atualizado
2024-01-19
·
CVE-2023-35887
CVSS v3.1
5.0
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache MINA versions 1.0 through 2.9.3
Description
The issue is related to the exposure of sensitive information to unauthorized actors in Apache MINA SSHD SFTP servers that use a RootedFileSystem. Logged users may be able to discover "exists/does not exist" information about items outside the rooted tree via paths including parent navigation ("..") beyond the root, or involving symlinks.
Recommendations
For Apache MINA versions 1.0 through 2.9.3, upgrade to version 2.10 to resolve the issue.
As a temporary workaround, consider restricting access to the RootedFileSystem to minimize the risk of exploitation.
Correção
Path traversal
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Apache Mina