CVE-2023-35887 MEDIUM

CVE-2023-35887: Apache MINA SSHD: Information disclosure bugs with RootedFilesystem

Vendor Apache Software Foundation
Product Apache MINA SSHD
Weakness CWE-22 · Path traversal
Published July 10, 2023
Last update October 7, 2024

CVSS base score

5.0/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

What the vulnerability does

Description

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache MINA. In SFTP servers implemented using Apache MINA SSHD that use a RootedFileSystem, logged users may be able to discover "exists/does not exist" information about items outside the rooted tree via paths including parent navigation ("..") beyond the root, or involving symlinks. This issue affects Apache MINA: from 1.0 before 2.10. Users are recommended to upgrade to 2.10

Key dates

Disclosure timeline

July 10, 2023 CVE published
October 7, 2024 Record updated