跳转到帖子

Red Hat JBossEAP: Path Traversal (CVE-2023-35887)

recommended_posts

发布于
  • Members

Red Hat JBossEAP: Path Traversal (CVE-2023-35887)

Severity
4
CVSS
(AV:N/AC:L/Au:S/C:P/I:N/A:N)
Published
07/10/2023
Created
09/20/2024
Added
09/19/2024
Modified
12/20/2024

Description

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache MINA. In SFTP servers implemented using Apache MINA SSHD that use a RootedFileSystem, logged users may be able to discover "exists/does not exist" information about items outside the rooted tree via paths including parent navigation ("..") beyond the root, or involving symlinks. This issue affects Apache MINA: from 1.0 before 2.10. Users are recommended to upgrade to 2.10. A flaw was found in Apache Mina SSHD that could be exploited on certain SFTP servers implemented using the Apache Mina RootedFileSystem. This issue could permit authenticated users to view information outside of their permissions scope.

Solution(s)

  • red-hat-jboss-eap-upgrade-latest

References

  • https://attackerkb.com/topics/cve-2023-35887
  • CVE - 2023-35887
  • https://access.redhat.com/security/cve/CVE-2023-35887
  • https://bugzilla.redhat.com/show_bug.cgi?id=2240036
  • https://access.redhat.com/errata/RHSA-2023:7637
  • https://access.redhat.com/errata/RHSA-2023:7638
  • https://access.redhat.com/errata/RHSA-2023:7639
  • https://access.redhat.com/errata/RHSA-2023:7641
  • https://access.redhat.com/errata/RHSA-2024:1192
  • https://access.redhat.com/errata/RHSA-2024:1193
  • https://access.redhat.com/errata/RHSA-2024:1194
View more
  • 查看数 698
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。
注意:你的帖子需要版主批准后才能看到。

游客
回帖…