Class org.apache.sshd.server.keyprovider.SimpleGeneratorHostKeyProvider in Apache MINA SSHD <= 2.9.1 uses Java deserialization to load a serialized java.security.PrivateKey. The class is one of several implementations that an implementor using Apache MINA SSHD can choose for loading the host keys of an SSH server.
References
Configurations
History
16 Feb 2024, 13:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
07 Nov 2023, 03:54
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2022-11-16 09:15
Updated : 2024-02-28 19:29
NVD link : CVE-2022-45047
Mitre link : CVE-2022-45047
CVE.ORG link : CVE-2022-45047
JSON object : View
Products Affected
apache
- sshd
CWE
CWE-502
Deserialization of Untrusted Data