CVE-2023-35887
published 2023-07-10CVE-2023-35887: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache MINA. In SFTP servers implemented using Apache…
PriorityP422medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
1.31%
67.4th percentile
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache MINA.
In SFTP servers implemented using Apache MINA SSHD that use a RootedFileSystem, logged users may be able to discover "exists/does not exist" information about items outside the rooted tree via paths including parent navigation ("..") beyond the root, or involving symlinks.
This issue affects Apache MINA: from 1.0 before 2.10. Users are recommended to upgrade to 2.10
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | sshd | >= 1.0.0 < 2.9.3 | 2.9.3 |
| apache_software_foundation | apache_mina_sshd | >= 1.0 < 2.10 | 2.10 |
| debian | libmina-sshd-java | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
vendor_oracle4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle JD Edwards Risk Matrix: Business Logic Infra SEC (Apache Mina SSHD) — CVE-2023-35887
vendor_oracle·2024-07-15·CVSS 4.3
CVE-2023-35887 [MEDIUM] Oracle Oracle JD Edwards Risk Matrix: Business Logic Infra SEC (Apache Mina SSHD) — CVE-2023-35887
Oracle Oracle JD Edwards Risk Matrix: Business Logic Infra SEC (Apache Mina SSHD) vulnerability
CVE: CVE-2023-35887
CVSS: 4.3
Protocol: SSH
Remote exploit: No
Affected versions: Network
Advisory: cpujul2024 (JUL 2024)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Users, roles, credentials, security (Apache Mina) — CVE-2023-35887
vendor_oracle·2024-04-15·CVSS 4.3
CVE-2023-35887 [MEDIUM] Oracle Oracle Fusion Middleware Risk Matrix: Users, roles, credentials, security (Apache Mina) — CVE-2023-35887
Oracle Oracle Fusion Middleware Risk Matrix: Users, roles, credentials, security (Apache Mina) vulnerability
CVE: CVE-2023-35887
CVSS: 4.3
Protocol: SSH
Remote exploit: No
Affected versions: Network
Advisory: cpuapr2024 (APR 2024)
Oracle
Oracle Oracle Retail Applications Risk Matrix: Internal Operations (Apache Mina SSHD) — CVE-2023-35887
vendor_oracle·2024-01-15·CVSS 4.3
CVE-2023-35887 [MEDIUM] Oracle Oracle Retail Applications Risk Matrix: Internal Operations (Apache Mina SSHD) — CVE-2023-35887
Oracle Oracle Retail Applications Risk Matrix: Internal Operations (Apache Mina SSHD) vulnerability
CVE: CVE-2023-35887
CVSS: 4.3
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpujan2024 (JAN 2024)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: General (Apache Mina SSHD) — CVE-2023-35887
vendor_oracle·2023-10-15·CVSS 4.3
CVE-2023-35887 [MEDIUM] Oracle Oracle Fusion Middleware Risk Matrix: General (Apache Mina SSHD) — CVE-2023-35887
Oracle Oracle Fusion Middleware Risk Matrix: General (Apache Mina SSHD) vulnerability
CVE: CVE-2023-35887
CVSS: 4.3
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpuoct2023 (OCT 2023)
Red Hat
apache-mina-sshd: information exposure in SFTP server implementations
vendor_redhat·2023-07-10·CVSS 5.0
CVE-2023-35887 [MEDIUM] CWE-22 apache-mina-sshd: information exposure in SFTP server implementations
apache-mina-sshd: information exposure in SFTP server implementations
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache MINA.
In SFTP servers implemented using Apache MINA SSHD that use a RootedFileSystem, logged users may be able to discover "exists/does not exist" information about items outside the rooted tree via paths including parent navigation ("..") beyond the root, or involving symlinks.
This issue affects Apache MINA: from 1.0 before 2.10. Users are recommended to upgrade to 2.10
A flaw was found in Apache Mina SSHD that could be exploited on certain SFTP servers implemented using the Apache Mina RootedFileSystem. This issue could permit authenticated users to view information outside of their permissions scope.
Packa
Debian
CVE-2023-35887: libmina-sshd-java - Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apac...
vendor_debian·2023·CVSS 5.0
CVE-2023-35887 [MEDIUM] CVE-2023-35887: libmina-sshd-java - Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apac...
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache MINA. In SFTP servers implemented using Apache MINA SSHD that use a RootedFileSystem, logged users may be able to discover "exists/does not exist" information about items outside the rooted tree via paths including parent navigation ("..") beyond the root, or involving symlinks. This issue affects Apache MINA: from 1.0 before 2.10. Users are recommended to upgrade to 2.10
Scope: local
forky: resolved
sid: resolved
trixie: resolved
GHSA
Apache MINA SSHD information disclosure vulnerability
ghsa·2023-07-10
CVE-2023-35887 [MEDIUM] CWE-200 Apache MINA SSHD information disclosure vulnerability
Apache MINA SSHD information disclosure vulnerability
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache MINA.
In SFTP servers implemented using Apache MINA SSHD that use a RootedFileSystem, logged users may be able to discover "exists/does not exist" information about items outside the rooted tree via paths including parent navigation ("..") beyond the root, or involving symlinks.
This issue affects Apache MINA: from 1.0 before 2.9.3 Users are recommended to upgrade to 2.9.3
Until version 2.1.0, some of the code affected by this vulnerability appeared in org.apache.sshd:sshd-core. Version 2.1.0 contains a [commit](https://github.com/apache/mina-sshd/commit/10de190e7d3f9189deb76b8d08c72334a1fe2df0) where the code was moved to t
OSV
Apache MINA SSHD information disclosure vulnerability
osv·2023-07-10
CVE-2023-35887 [MEDIUM] Apache MINA SSHD information disclosure vulnerability
Apache MINA SSHD information disclosure vulnerability
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache MINA.
In SFTP servers implemented using Apache MINA SSHD that use a RootedFileSystem, logged users may be able to discover "exists/does not exist" information about items outside the rooted tree via paths including parent navigation ("..") beyond the root, or involving symlinks.
This issue affects Apache MINA: from 1.0 before 2.9.3 Users are recommended to upgrade to 2.9.3
Until version 2.1.0, some of the code affected by this vulnerability appeared in org.apache.sshd:sshd-core. Version 2.1.0 contains a [commit](https://github.com/apache/mina-sshd/commit/10de190e7d3f9189deb76b8d08c72334a1fe2df0) where the code was moved to t
No detection rules found.
No public exploits indexed.
2023-07-10
Published