Sploitus

CVE-2023-35887

1 known exploit for CVE-2023-35887

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache MINA. In SFTP servers implemented using Apache MINA SSHD that use a RootedFileSystem, logged users may be able to discover "exists/does not exist" information about items outside the rooted tree via paths including parent navigation ("..") beyond the root, or involving symlinks. This issue affects Apache MINA: from 1.0 before 2.10. Users are recommended to upgrade to 2.10

Affected products
Apache Mina
Apache Sshd
< 2.9.3
Fix
Available
CVSS 3.1
5.0 MEDIUM
EPSS
1.3% (68th percentile)
Weakness
CWE-22
NVD status
Modified
Published
2023-07-10
CVE-2023-35887 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2023-35887

Proof-of-concept code and exploit modules indexed by Sploitus