Overview
About vulnerability
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache MINA.
In SFTP servers implemented using Apache MINA SSHD that use a RootedFileSystem, logged users may be able to discover “exists/does not exist” information about items outside the rooted tree via paths including parent navigation ("..") beyond the root, or involving symlinks.
This issue affects Apache MINA: from 1.0 before 2.9.3 Users are recommended to upgrade to 2.9.3
Until version 2.1.0, some of the code affected by this vulnerability appeared in org.apache.sshd:sshd-core. Version 2.1.0 contains a [commit](https://github.com/apache/mina-sshd/commit/10de190e7d3f9189deb76b8d08c72334a1fe2df0) where the code was moved to the package org.apache.sshd:sshd-common, which did not exist until version 2.1.0.
Details
- Affected product:
- Apache CXF , Spring , Wildfly , activemq , camel , gradle , jboss-ejb-client , jgit , jline , karaf , mina-sshd , org.apache.karaf.shell.core , sshd-common , sshd-core , sshd-osgi , wildfly
- Affected packages:
- activemq-ra @ 5.18.7 (+2210 more)