CVE-2022-45047
Summary
| CVE | CVE-2022-45047 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-11-16 09:15:00 UTC |
| Updated | 2023-11-07 03:54:00 UTC |
| Description | Class org.apache.sshd.server.keyprovider.SimpleGeneratorHostKeyProvider in Apache MINA SSHD <= 2.9.1 uses Java deserialization to load a serialized java.security.PrivateKey. The class is one of several implementations that an implementor using Apache MINA SSHD can choose for loading the host keys of an SSH server. |
Risk And Classification
Problem Types: CWE-502
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2022-45047: Apache MINA SSHD: Java unsafe deserialization vulnerability | CONFIRM | www.mail-archive.com | |
| CVE-2022-45047: Apache MINA SSHD: Java unsafe deserialization vulnerability | www.mail-archive.com | ||
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: The Apache MINA SSHD team would like to thank Zhang Zewei, NOFOCUS, for reporting this issue.
Legacy QID Mappings
- 20317 Oracle Database 21c Critical Patch Update - January 2023
- 20318 Oracle Database 19c Critical Patch Update - January 2023
- 20319 Oracle Database 19c Critical OJVM Patch Update - January 2023
- 241153 Red Hat Update for JBoss Enterprise Application Platform 7.4.9 (RHSA-2023:0554)
- 241154 Red Hat Update for JBoss Enterprise Application Platform 7.4.9 (RHSA-2023:0552)
- 241155 Red Hat Update for JBoss Enterprise Application Platform 7.4.9 (RHSA-2023:0553)
- 241180 Red Hat OpenShift Container Platform 4.10 Security Update (RHSA-2023:0560)
- 241214 Red Hat OpenShift Container Platform 4.9 Security Update (RHSA-2023:0777)
- 377908 Oracle Coherence January 2023 Critical Patch Update (CPUJAN2023)
- 378427 Oracle PeopleSoft Enterprise PeopleTools Product Multiple Vulnerabilities (CPUAPR2023)
- 755655 SUSE Enterprise Linux Security Update for apache-parent, apache-sshd (SUSE-SU-2024:0224-1)
- 770173 Red Hat OpenShift Container Platform 4.10 Security Update (RHSA-2023:0560)
- 770178 Red Hat OpenShift Container Platform 4.9. Security Update (RHSA-2023:0777)