Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-35887
HistoryJul 10, 2023 - 4:15 p.m.

Design/Logic Flaw

2023-07-1016:15:00
PRIOn knowledge base
www.prio-n.com
12
logic flaw
apache mina
sensitive information
unauthorized actor
vulnerability
sftp
rootedfilesystem
symlinks
upgrade

4.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

26.8%

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache MINA.

In SFTP servers implemented using Apache MINA SSHD that use a RootedFileSystem, logged users may be able to discover “exists/does not exist” information about items outside the rooted tree via paths including parent navigation (“…”) beyond the root, or involving symlinks.

This issue affects Apache MINA: from 1.0 before 2.10. Users are recommended to upgrade to 2.10

CPENameOperatorVersion
sshdge1.0.0
sshdlt2.9.3

4.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

26.8%