VDB
Sign up
MEDIUM5.0

GHSA-mjmq-gwgm-5qhm

Apache MINA SSHD information disclosure vulnerability

Quick fix

GHSA-mjmq-gwgm-5qhm — org.apache.sshd:sshd-common: upgrade to the fixed version with the command below.

# pom.xml: bump <version>2.9.3</version> for org.apache.sshd:sshd-common

Details

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache MINA.

In SFTP servers implemented using Apache MINA SSHD that use a RootedFileSystem, logged users may be able to discover "exists/does not exist" information about items outside the rooted tree via paths including parent navigation ("..") beyond the root, or involving symlinks.

This issue affects Apache MINA: from 1.0 before 2.9.3 Users are recommended to upgrade to 2.9.3

Until version 2.1.0, some of the code affected by this vulnerability appeared in org.apache.sshd:sshd-core. Version 2.1.0 contains a [commit](https://github.com/apache/mina-sshd/commit/10de190e7d3f9189deb76b8d08c72334a1fe2df0) where the code was moved to the package org.apache.sshd:sshd-common, which did not exist until version 2.1.0.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.apache.sshd:sshd-common
Introduced in: 2.1.0Fixed in: 2.9.3
Fix# pom.xml: bump <version>2.9.3</version> for org.apache.sshd:sshd-common
Maven/org.apache.sshd:sshd-sftp
Introduced in: 1.0.0Fixed in: 2.9.3
Fix# pom.xml: bump <version>2.9.3</version> for org.apache.sshd:sshd-sftp
Maven/org.apache.sshd:sshd-core
Introduced in: 1.0.0Fixed in: 2.1.0
Fix# pom.xml: bump <version>2.1.0</version> for org.apache.sshd:sshd-core

References