Lucene search

K
cvelistApacheCVELIST:CVE-2022-45047
HistoryNov 16, 2022 - 12:00 a.m.

CVE-2022-45047 Apache MINA SSHD: Java unsafe deserialization vulnerability

2022-11-1600:00:00
CWE-502
apache
www.cve.org
4
apache mina sshd
deserialization vulnerability
simplegeneratorhostkeyprovider
java
privatekey
ssh server

9.6 High

AI Score

Confidence

High

0.01 Low

EPSS

Percentile

83.7%

Class org.apache.sshd.server.keyprovider.SimpleGeneratorHostKeyProvider in Apache MINA SSHD <= 2.9.1 uses Java deserialization to load a serialized java.security.PrivateKey. The class is one of several implementations that an implementor using Apache MINA SSHD can choose for loading the host keys of an SSH server.

CNA Affected

[
  {
    "vendor": "Apache Software Foundation",
    "product": "Apache MINA SSHD",
    "versions": [
      {
        "version": "unspecified",
        "lessThanOrEqual": "2.9.1",
        "status": "affected",
        "versionType": "custom"
      }
    ]
  }
]

9.6 High

AI Score

Confidence

High

0.01 Low

EPSS

Percentile

83.7%