CVE-2023-35887
Last modified
CVE-2023-35887 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache MINA. In SFTP servers implemented using Apache MINA SSHD that use a RootedFileSystem, logged users may be able to discover "exists/does not exist" information about items outside the rooted tree via paths including parent navigation ("..") beyond the root, or involving symlinks. This issue affects Apache MINA: from 1.0 before 2.10. Users are recommended to upgrade to 2.10 . EPSS estimates a 0.98% chance of exploitation in the next 30 days.
Description
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache MINA. In SFTP servers implemented using Apache MINA SSHD that use a RootedFileSystem, logged users may be able to discover "exists/does not exist" information about items outside the rooted tree via paths including parent navigation ("..") beyond the root, or involving symlinks. This issue affects Apache MINA: from 1.0 before 2.10. Users are recommended to upgrade to 2.10
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Sshd | >= 1.0.0, < 2.9.3 |
References
- https://lists.apache.org/thread/b9qgtqvhnvgfpn0w1gz918p21p53tqk2Mailing List, Vendor Advisory
- https://lists.apache.org/thread/b9qgtqvhnvgfpn0w1gz918p21p53tqk2Mailing List, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-35887?
How severe is CVE-2023-35887?
How do I fix CVE-2023-35887?
Are you affected by CVE-2023-35887?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
