PT-2026-61721 · Apache · Apache Mina Sshd
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Apache MINA SSHD versions prior to 2.19.0
Apache MINA SSHD versions prior to 3.0.0-M5
Description
Improper input validation in the
sshd-git component of Apache MINA SSHD, specifically within the GitPgmCommandFactory, allows an authenticated SSH user to execute arbitrary JGit commands. This can lead to unauthorized file writes at arbitrary locations on the server, for example, by using the git archive command with the --output option.Recommendations
Upgrade to version 2.19.0.
Upgrade to version 3.0.0-M5.
As a temporary mitigation, avoid configuring the
GitPgmCommandFactory on the server.Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Mina Sshd