{"schema_version":"1.9.0","id":"CVE-2023-35887","published":"2023-07-10T09:28:54.987Z","modified":"2026-08-12T03:51:19.797474197Z","aliases":["GHSA-mjmq-gwgm-5qhm"],"related":["CGA-fr3h-rgrv-p2gx"],"summary":"Apache MINA SSHD: Information disclosure bugs with RootedFilesystem","details":"Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache MINA.\n\nIn SFTP servers implemented using Apache MINA SSHD that use a RootedFileSystem, logged users may be able to discover \"exists/does not exist\" information about items outside the rooted tree via paths including parent navigation (\"..\") beyond the root, or involving symlinks.\n\nThis issue affects Apache MINA: from 1.0 before 2.10. Users are recommended to upgrade to 2.10\n","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/mina-sshd","events":[{"introduced":"f11c73d4fb7836e8ae8ccb4ed8301dc42c0968ac"},{"fixed":"a377173417abd8d20541d73d97d739d440d895dc"}],"database_specific":{"cpe":"cpe:2.3:a:apache:sshd:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.0.0"},{"fixed":"2.9.3"}],"source":"CPE_RANGE"}}],"versions":["sshd-2.9.2","sshd-2.9.1","sshd-2.9.0","sshd-2.8.0","sshd-2.7.0","sshd-2.6.0","sshd-2.5.1","sshd-2.5.0","sshd-2.4.0","sshd-2.3.0","sshd-2.2.0","sshd-2.1.0","sshd-2.0.0","sshd-1.7.0","sshd-1.6.0","sshd-1.5.0","sshd-1.4.0","sshd-1.3.0","sshd-1.2.0","sshd-1.1.0","sshd-1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-35887.json"}}],"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/35xxx/CVE-2023-35887.json"},{"type":"ADVISORY","url":"https://lists.apache.org/thread/b9qgtqvhnvgfpn0w1gz918p21p53tqk2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-35887"}],"database_specific":{"cna_assigner":"apache","cwe_ids":["CWE-22"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/35xxx/CVE-2023-35887.json","unresolved_ranges":[{"extracted_events":[{"introduced":"1.0"},{"fixed":"2.10"}],"source":"AFFECTED_FIELD"},{"extracted_events":[{"introduced":"1.0"},{"fixed":"2.10"}],"source":"DESCRIPTION"}]},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N"}]}