๐Ÿ” CVE Alert

CVE-2022-45047

UNKNOWN 0.0

Apache MINA SSHD: Java unsafe deserialization vulnerability

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Class org.apache.sshd.server.keyprovider.SimpleGeneratorHostKeyProvider in Apache MINA SSHD <= 2.9.1 uses Java deserialization to load a serialized java.security.PrivateKey. The class is one of several implementations that an implementor using Apache MINA SSHD can choose for loading the host keys of an SSH server.

CWE CWE-502
Vendor apache software foundation
Product apache mina sshd
Published Nov 16, 2022
Last Updated Aug 3, 2024
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache mina sshd

Be the first to know when new unknown vulnerabilities affecting apache software foundation apache mina sshd are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Apache Software Foundation / Apache MINA SSHD
unspecified โ‰ค 2.9.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
mail-archive.com: https://www.mail-archive.com/dev%40mina.apache.org/msg39312.html security.netapp.com: https://security.netapp.com/advisory/ntap-20240216-0008/

Credits

The Apache MINA SSHD team would like to thank Zhang Zewei, NOFOCUS, for reporting this issue.