Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Address CVE-2023-48795 (details are already public) #453

Closed
martin-traverse opened this issue Jan 14, 2024 · 1 comment
Closed

Address CVE-2023-48795 (details are already public) #453

martin-traverse opened this issue Jan 14, 2024 · 1 comment
Labels
duplicate An issue that is a duplicate of another one.

Comments

@martin-traverse
Copy link

Version

2.11

Bug description

Using Apache SSHD is now causing projects to fail security scanning due to CVE-2023-48795. Appreciate this is a much wider issue than just this project. Details of the vulnerability are already available publicly here:

https://nvd.nist.gov/vuln/detail/CVE-2023-48795#range-10212309

Are there any plans to address this issue? For example by disabling use of the affected extensions unless some explicit configuration is passed, e.g. AllowUnsafeExtensions?

Actual behavior

Using the Apache SSHD libraries causes projects to fail vulnerability scanning. Currently the only option is to use an exclusion for this vulnerability, so it can be exploited if a site is misconfigured.

Expected behavior

Affected extensions are disabled by default so the vulnerability cannot be exploited without explicit configuration. An updated version of SSHD passes security scanning.

Relevant log output

No response

Other information

No response

@tomaswolf
Copy link
Member

This is a duplicate of #445. Will be fixed in Apache MINA SSHD 2.12.0, the release is currently in the voting phase, see mail thread.

@tomaswolf tomaswolf added the duplicate An issue that is a duplicate of another one. label Jan 14, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
duplicate An issue that is a duplicate of another one.
Projects
None yet
Development

No branches or pull requests

2 participants