Done
Details
Assignee
UnassignedUnassignedReporter
DenisDenisPriority
P2RCA Group
TBDTestRail: Cases
Open TestRail: CasesTestRail: Runs
Open TestRail: Runs
Details
Details
Assignee
Unassigned
UnassignedReporter
Denis
DenisPriority
RCA Group
TBD
TestRail: Cases
Open TestRail: Cases
TestRail: Runs
Open TestRail: Runs
Created August 30, 2024 at 12:10 PM
Updated October 10, 2024 at 3:31 PM
Resolved October 10, 2024 at 3:12 PM
Severity: high
Link:
Package Name: Apache MINA SSHD
Current version: 2.9.3 / fixed in 2.12.0
Like many other SSH implementations, Apache MINA SSHD suffered from the issue that is more widely known as CVE-2023-48795. An attacker that can intercept traffic between client and server could drop certain packets from the stream, potentially causing client and server to consequently end up with a connection for which some security features have been downgraded or disabled, aka a Terrapin attack The mitigations to prevent this type of attack were implemented in Apache MINA SSHD 2.12.0, both client and server side. Users are recommended to upgrade to at least this version. Note that both the client and the server implementation must have mitigations applied against this issue, otherwise the connection may still be affected.
Modules impacted:
mod-invoice
Thunderjet
5.8.2
Affected are all versions >= 5.7.0 because 5.7.0 (Poppy version) is the first mod-invoice version with SFTP.