Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-45047
HistoryNov 16, 2022 - 9:15 a.m.

Deserialization of untrusted data

2022-11-1609:15:00
PRIOn knowledge base
www.prio-n.com
13
deserialization
untrusted data
apache mina sshd
simple generator host key provider
vulnerability

9.2 High

AI Score

Confidence

High

0.01 Low

EPSS

Percentile

83.7%

Class org.apache.sshd.server.keyprovider.SimpleGeneratorHostKeyProvider in Apache MINA SSHD <= 2.9.1 uses Java deserialization to load a serialized java.security.PrivateKey. The class is one of several implementations that an implementor using Apache MINA SSHD can choose for loading the host keys of an SSH server.

CPENameOperatorVersion
sshdle2.9.1

9.2 High

AI Score

Confidence

High

0.01 Low

EPSS

Percentile

83.7%