Lucene search

K
osvGoogleOSV:GHSA-Q446-82VQ-W674
HistoryMay 13, 2022 - 1:09 a.m.

Improper Limitation of a Pathname to a Restricted Directory in JCraft JSch

2022-05-1301:09:33
Google
osv.dev
27

0.008 Low

EPSS

Percentile

82.1%

Directory traversal vulnerability in JCraft JSch before 0.1.54 on Windows, when the mode is ChannelSftp.OVERWRITE, allows remote SFTP servers to write to arbitrary files via a …\ (dot dot backslash) in a response to a recursive GET command.