MEDIUMMaven →
Apache MINA SSHD information disclosure vulnerability
Apache MINA SSHD information disclosure vulnerability
Affected packages
- org.apache.sshd:sshd-common— 2.1.0 → 2.9.3
- org.apache.sshd:sshd-core— 1.0.0 → 2.1.0
- org.apache.sshd:sshd-sftp— 1.0.0 → 2.9.3
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://nvd.nist.gov/vuln/detail/CVE-2023-35887
- https://github.com/apache/mina-sshd/pull/362
- https://github.com/apache/mina-sshd/commit/10de190e7d3f9189deb76b8d08c72334a1fe2df0
- https://github.com/apache/mina-sshd/commit/a61e93035f06bff8fc622ad94870fb773d48b9f0
- https://github.com/apache/mina-sshd/commit/c20739b43aab0f7bf2ccad982a6cb37b9d5a8a0b
- https://github.com/apache/mina-sshd
- https://issues.apache.org/jira/browse/SSHD-1324
- https://lists.apache.org/thread/b9qgtqvhnvgfpn0w1gz918p21p53tqk2
Structured record: https://osv.dev/vulnerability/GHSA-mjmq-gwgm-5qhm
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta