CVE-2023-35887
MEDIUMApache MINA SSHD < 2.9.3 - Path Traversal via Parent Navigation
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-35887. PoCs published by shoucheng3.
AI-analyzed exploit summary This repository contains a proof-of-concept exploit for CVE-2023-35887, targeting Apache MINA SSHD. The exploit appears to leverage vulnerabilities in the SSH protocol implementation, potentially allowing remote code execution or other offensive techniques.
Description
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache MINA. In SFTP servers implemented using Apache MINA SSHD that use a RootedFileSystem, logged users may be able to discover "exists/does not exist" information about items outside the rooted tree via paths including parent navigation ("..") beyond the root, or involving symlinks. This issue affects Apache MINA: from 1.0 before 2.10. Users are recommended to upgrade to 2.10
Exploits (1)
This repository contains a proof-of-concept exploit for CVE-2023-35887, targeting Apache MINA SSHD. The exploit appears to leverage vulnerabilities in the SSH protocol implementation, potentially allowing remote code execution or other offensive techniques.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N