QID 981829

QID 981829: Java (maven) Security Update for org.apache.sshd:sshd-core (GHSA-9279-7hph-r3xw)

A vulnerability in sshd-core of Apache Mina SSHD allows an attacker to overflow the server causing an OutOfMemory error. This issue affects the SFTP and port forwarding features of Apache Mina SSHD version 2.0.0 and later versions. It was addressed in Apache Mina SSHD 2.7.0

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution
    Customers are advised to refer to GHSA-9279-7hph-r3xw for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 981829

    Software Advisories
    Advisory ID Software Component Link
    GHSA-9279-7hph-r3xw org.apache.sshd:sshd-core URL Logo github.com/advisories/GHSA-9279-7hph-r3xw
    GHSA-9279-7hph-r3xw org.apache.sshd:sshd-mina URL Logo github.com/advisories/GHSA-9279-7hph-r3xw