A vulnerability was discovered in JSch that allows a malicious sftp server to force a client-side relative path traversal in jsch's implementation for recursive sftp-get. An attacker could leverage this to write files outside the client's download basedir with effective permissions of the jsch sftp client process.
Find out more about CVE-2016-5725 from the MITRE CVE dictionary dictionary and NIST NVD.
Base Score | 2.6 |
---|---|
Base Metrics | AV:N/AC:H/Au:N/C:N/I:P/A:N |
Access Vector | Network |
Access Complexity | High |
Authentication | None |
Confidentiality Impact | None |
Integrity Impact | Partial |
Availability Impact | None |
CVSS3 Base Score | 4.2 |
---|---|
CVSS3 Base Metrics | CVSS:3.0/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:H/A:N |
Attack Vector | Network |
Attack Complexity | High |
Privileges Required | High |
User Interaction | Required |
Scope | Unchanged |
Confidentiality | None |
Integrity Impact | High |
Availability Impact | None |
Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).
Platform | Errata | Release Date |
---|---|---|
Red Hat JBoss A-MQ 6.3 | RHSA-2017:3115 | 2017-11-02 |
Red Hat JBoss Fuse 6.3 | RHSA-2017:3115 | 2017-11-02 |
Platform | Package | State |
---|---|---|
Red Hat Virtualization 4 | jsch | Will not fix |
Red Hat Software Collections for Red Hat Enterprise Linux | rh-java-common-jsch | Not affected |
Red Hat Satellite 6 | jsch | Will not fix |
Red Hat OpenShift Enterprise 2 | jsch | Will not fix |
Red Hat JBoss Operations Network 3 | jsch | Not affected |
Red Hat JBoss Fuse Service Works 6 | jsch | Will not fix |
Red Hat JBoss Data Virtualization 6 | jsch | Will not fix |
Red Hat JBoss BRMS 6 | jsch | Will not fix |
Red Hat JBoss BPMS 6 | jsch | Will not fix |
Red Hat Enterprise Linux 7 | jsch | Not affected |
Red Hat Enterprise Linux 6 | jsch | Not affected |
Red Hat Enterprise Linux 5 | jsch | Not affected |