Bug 2503052 (CVE-2026-56452)
| Summary: | CVE-2026-56452 org.apache.sshd/sshd-scp: Apache MINA SSHD: Path traversal via SCP allows arbitrary file write | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | Keywords: | Security |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in the sshd-scp component of Apache MINA SSHD, a Java library for client-side and server-side SSH. The implementation for receiving files or directories via Secure Copy Protocol (SCP) did not properly validate filenames. A remote attacker could exploit this by sending specially crafted filenames containing path traversal sequences, leading to files being written to arbitrary locations on the system. This could result in unauthorized modification of system files or data.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2521828, 2521829 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-07-20 21:02:07 UTC
|