PT-2023-7055 · Apache · Apache Mina
Andrew Pikler
·
Published
2023-07-10
·
Updated
2024-01-19
·
CVE-2023-35887
CVSS v3.1
5.0
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache MINA versions 1.0 through 2.9.3
Description
The issue is related to the exposure of sensitive information to unauthorized actors in Apache MINA SSHD SFTP servers that use a RootedFileSystem. Logged users may be able to discover "exists/does not exist" information about items outside the rooted tree via paths including parent navigation ("..") beyond the root, or involving symlinks.
Recommendations
For Apache MINA versions 1.0 through 2.9.3, upgrade to version 2.10 to resolve the issue.
As a temporary workaround, consider restricting access to the RootedFileSystem to minimize the risk of exploitation.
Fix
Path traversal
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Mina