CVE-2023-35887

unknown
Published 2023-07-10 · Modified 2026-04-10
CVSS v3
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
CVSS v2
VIR risk

Description

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache MINA. In SFTP servers implemented using Apache MINA SSHD that use a RootedFileSystem, logged users may be able to discover "exists/does not exist" information about items outside the rooted tree via paths including parent navigation ("..") beyond the root, or involving symlinks. This issue affects Apache MINA: from 1.0 before 2.10. Users are recommended to upgrade to 2.10

Predictions

Exploit likelihood
30%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2023-35887

OS impact

OSVersionStatusFixed in
debian debianforkyfixed0
debian debiansidfixed0
debian debiantrixiefixed0

Package impact

EcosystemPackageVulnerableFixed
java Mavenorg.apache.sshd:sshd-common>=2.1.0,<2.9.32.9.3
java Mavenorg.apache.sshd:sshd-sftp>=1.0.0,<2.9.32.9.3
java Mavenorg.apache.sshd:sshd-core>=1.0.0,<2.1.02.1.0

References

Verify integrity in audit chain (admin only). AS-IS.