PT-2026-45380 · Apache · Apache Mina Sshd
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Apache MINA SSHD versions prior to 2.18.0
Apache MINA SSHD versions 3.0.0-M1 through 3.0.0-M3
Description
A path traversal issue exists in the
org.apache.sshd:sshd-git bundle. Due to insufficient path validation in git-upload-pack, git-receive-pack, and other git operations, users authenticated via SSH can access git repositories located outside the configured git server root directory. Path traversal is a vulnerability that allows an attacker to access files or directories that are stored outside the web root folder by manipulating variables such as file paths.Recommendations
Upgrade to Apache MINA SSHD version 2.18.0.
Upgrade to Apache MINA SSHD version 3.0.0-M4.
Implement additional security controls to govern access to git repositories and allowed operations instead of relying solely on file system layout and permissions.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Mina Sshd