GHSA-2326-hx7g-3m9r

    Dashboard / Vulnerabilities / GHSA-2326-hx7g-3m9r

    GHSA-2326-hx7g-3m9r

    Published: 12 Aug 2024Last Modified: 10 Sept 2026

    Summary: Apache MINA SSHD: integrity check bypass

    Details: Like many other SSH implementations, Apache MINA SSHD suffered from the issue that is more widely known as CVE-2023-48795. An attacker that can intercept traffic between client and server could drop certain packets from the stream, potentially causing client and server to consequently end up with a connection for which some security features have been downgraded or disabled, aka a Terrapin attack The mitigations to prevent this type of attack were implemented in Apache MINA SSHD 2.12.0, both client and server side. Users are recommended to upgrade to at least this version. Note that both the client and the server implementation must have mitigations applied against this issue, otherwise the connection may still be affected.

    Affected packages

    Package

    Name: org.apache.sshd:sshd-common

    Purl: pkg:maven/org.apache.sshd/sshd-common

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -2.12.0

    Affected versions

    2.1.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High