CVE-2024-41909 - org.apache.sshd_sshd-common - Analysis of vulnerability - Quesnelia

Description

Severity: high
Link:
Package Name: Apache MINA SSHD
Current version: 2.9.3 / fixed in 2.12.0

Like many other SSH implementations, Apache MINA SSHD suffered from the issue that is more widely known as CVE-2023-48795. An attacker that can intercept traffic between client and server could drop certain packets from the stream, potentially causing client and server to consequently end up with a connection for which some security features have been downgraded or disabled, aka a Terrapin attack The mitigations to prevent this type of attack were implemented in Apache MINA SSHD 2.12.0, both client and server side. Users are recommended to upgrade to at least this version. Note that both the client and the server implementation must have mitigations applied against this issue, otherwise the connection may still be affected.

Modules impacted:

mod-invoice

Thunderjet

5.8.2

Affected are all versions >= 5.7.0 because 5.7.0 (Poppy version) is the first mod-invoice version with SFTP.

Checklist

hide

Activity

Show:

Julian LadischOctober 8, 2024 at 10:45 AM

Backport has been released for both Poppy and Quesnelia. Jira can be closed as done and unembargoed.

Done

Details

Assignee

Reporter

Priority

RCA Group

TBD

TestRail: Cases

Open TestRail: Cases

TestRail: Runs

Open TestRail: Runs

Created August 30, 2024 at 12:10 PM
Updated October 10, 2024 at 3:31 PM
Resolved October 10, 2024 at 3:12 PM
TestRail: Cases
TestRail: Runs