Apache Software Foundation Apache MINA SSHD是Apache Software Foundation基金会的SSH服务器实现库。 Apache MINA SSHD 2.0.0至2.18.0版本和3.0.0-M1至3.0.0-M4版本存在输入验证错误漏洞,该漏洞源于sshd-git组件中的GitPgmCommandFactory允许已通过SSH身份验证的用户执行任意JGit命令,包括通过git archive的--output选项在任意位置写入文件。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache MINA SSHD | 2.0.0≤ 2.18.0 |
affected |
3.0.0-M1≤ 3.0.0-M4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache MINA SSHD | 2.0.0 ~ 2.18.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-56452 | 7.5 HIGH | Apache MINA SSHD: Path traversal in SCP file reception |
| CVE-2026-56624 | 7.3 HIGH | Apache MINA SSHD: SSH certificate options lack validations |
| CVE-2026-56623 | 7.1 HIGH | Apache MINA SSHD: Path traversal in org.apache.sshd:sshd-git on Windows |
| CVE-2026-63071 | Apache Syncope: RCE via Groovy Sandbox bypass | |
| CVE-2026-53405 | Apache Syncope: Remote Code Execution via Flowable BPMN Groovy ScriptTask | |
| CVE-2026-53421 | Apache Syncope: Remote Code Execution via Scripted Connector | |
| CVE-2026-57308 | Apache Syncope: SQL injection vulnerability in Audit Events search | |
| CVE-2026-62183 | Apache Syncope: User self-service privilege escalation | |
| CVE-2026-62418 | Apache Syncope: Low-privileged authenticated SSRF in Connectors and Resources check |
No comments yet