PT-2023-7055 · Apache · Apache Mina

Andrew Pikler

·

Published

2023-07-10

·

Updated

2024-01-19

·

CVE-2023-35887

CVSS v3.1

5.0

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache MINA versions 1.0 through 2.9.3
Description The issue is related to the exposure of sensitive information to unauthorized actors in Apache MINA SSHD SFTP servers that use a RootedFileSystem. Logged users may be able to discover "exists/does not exist" information about items outside the rooted tree via paths including parent navigation ("..") beyond the root, or involving symlinks.
Recommendations For Apache MINA versions 1.0 through 2.9.3, upgrade to version 2.10 to resolve the issue. As a temporary workaround, consider restricting access to the RootedFileSystem to minimize the risk of exploitation.

Fix

Path traversal

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2023-08077
CVE-2023-35887
GHSA-MJMQ-GWGM-5QHM
OESA-2024-1079
RHSA-2023:7637
RHSA-2023:7638
RHSA-2023:7639
RHSA-2024:1192
RHSA-2024:1193

Affected Products

Apache Mina