CVE-2023-35887

    Dashboard / Vulnerabilities / CVE-2023-35887

    CVE-2023-35887

    Published: 10 Jul 2023Last Modified: 12 Aug 2026

    Summary: Apache MINA SSHD: Information disclosure bugs with RootedFilesystem

    Details: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache MINA. In SFTP servers implemented using Apache MINA SSHD that use a RootedFileSystem, logged users may be able to discover "exists/does not exist" information about items outside the rooted tree via paths including parent navigation ("..") beyond the root, or involving symlinks. This issue affects Apache MINA: from 1.0 before 2.10. Users are recommended to upgrade to 2.10

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- f11c73d4fb7836e8ae8ccb4ed8301dc42c0968ac

    Affected versions

    sshd-2.9.2
    sshd-2.9.1
    sshd-2.9.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2023-35887 | CVE-DB