Apache MINA SSHD: integrity check bypass
Published Aug 12, 2024
8.2
HIGHCVSS 4.0
EPSS 0.58%
Description
Like many other SSH implementations, Apache MINA SSHD suffered from the issue that is more widely known as CVE-2023-48795. An attacker that can intercept traffic between client and server could drop certain packets from the stream, potentially causing client and server to consequently end up with a connection for which some security features have been downgraded or disabled, aka a Terrapin attack
The mitigations to prevent this type of attack were implemented in Apache MINA SSHD 2.12.0, both client and server side. Users are recommended to upgrade to at least this version. Note that both the client and the server implementation must have mitigations applied against this issue, otherwise the connection may still be affected.
Affected products
-
- Version 0StatusaffectedConstraints<=2.11.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Apache Software Foundation | Apache MINA SSHD | unaffected |
|
No data.
EAP 8.0.1
n/a
Fixed · RHSA-2024:1194
A-MQ Clients 2
sshd-common
Will not fix
OpenShift Developer Tools and Services
jenkins
Not affected
Red Hat Data Grid 8
org.apache.sshd/apache-sshd
Not affected
Red Hat Data Grid 8
sshd-common
Not affected
Red Hat Fuse 7
sshd-common
Will not fix
Red Hat Integration Camel K 1
sshd-common
Will not fix
Red Hat JBoss Enterprise Application Platform 7
org.apache.sshd/apache-sshd
Not affected
Red Hat JBoss Enterprise Application Platform 7
sshd-common
Not affected
Red Hat JBoss Enterprise Application Platform 8
org.apache.sshd/apache-sshd
Not affected
Red Hat JBoss Enterprise Application Platform 8
sshd-common
Affected
Red Hat JBoss Enterprise Application Platform 8
sshd-common-2.12.1.redhat
Not affected
Red Hat JBoss Enterprise Application Platform Expansion Pack
org.apache.sshd/apache-sshd
Not affected
Red Hat JBoss Enterprise Application Platform Expansion Pack
sshd-common
Not affected
Red Hat JBoss Web Server 6
sshd-common
Not affected
Red Hat OpenShift Container Platform 3.11
jenkins
Will not fix
Red Hat OpenShift Container Platform 3.11
jenkins-2-plugins
Will not fix
Red Hat Process Automation 7
sshd-common
Will not fix
Red Hat Single Sign-On 7
sshd-common
Will not fix
Red Hat Virtualization 4
apache-sshd
Will not fix
Red Hat build of Apache Camel - HawtIO 4
sshd-common
Not affected
Red Hat build of Apache Camel 4 for Quarkus 3
sshd-common
Not affected
Red Hat build of Apache Camel for Spring Boot 3
sshd-common
Will not fix
Red Hat build of Apache Camel for Spring Boot 4
sshd-common
Not affected
Red Hat build of Quarkus
org.apache.sshd.sshd-common
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| EAP 8.0.1 | n/a | Fixed | RHSA-2024:1194 |
| A-MQ Clients 2 | sshd-common | Will not fix | n/a |
| OpenShift Developer Tools and Services | jenkins | Not affected | n/a |
| Red Hat Data Grid 8 | org.apache.sshd/apache-sshd | Not affected | n/a |
| Red Hat Data Grid 8 | sshd-common | Not affected | n/a |
| Red Hat Fuse 7 | sshd-common | Will not fix | n/a |
| Red Hat Integration Camel K 1 | sshd-common | Will not fix | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | org.apache.sshd/apache-sshd | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | sshd-common | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | org.apache.sshd/apache-sshd | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | sshd-common | Affected | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | sshd-common-2.12.1.redhat | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | org.apache.sshd/apache-sshd | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | sshd-common | Not affected | n/a |
| Red Hat JBoss Web Server 6 | sshd-common | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.11 | jenkins | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.11 | jenkins-2-plugins | Will not fix | n/a |
| Red Hat Process Automation 7 | sshd-common | Will not fix | n/a |
| Red Hat Single Sign-On 7 | sshd-common | Will not fix | n/a |
| Red Hat Virtualization 4 | apache-sshd | Will not fix | n/a |
| Red Hat build of Apache Camel - HawtIO 4 | sshd-common | Not affected | n/a |
| Red Hat build of Apache Camel 4 for Quarkus 3 | sshd-common | Not affected | n/a |
| Red Hat build of Apache Camel for Spring Boot 3 | sshd-common | Will not fix | n/a |
| Red Hat build of Apache Camel for Spring Boot 4 | sshd-common | Not affected | n/a |
| Red Hat build of Quarkus | org.apache.sshd.sshd-common | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Above CVE is classified as a moderate severity issue rather than an important one due to its reliance on specific conditions for exploitation. The vulnerability, known as a Terrapin attack, requires an attacker to have the capability to intercept and manipulate packets between the SSH client and server. This level of access is not commonly available in most network environments, reducing the likelihood of widespread exploitation. Additionally, the impact of the attack—where security features may be downgraded or disabled—depends on the attacker's ability to perform packet drops without detection, which further limits the potential for significant damage.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (14)
- https://access.redhat.com/security/cve/CVE-2024-41909 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2304442 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-2458 Advisory
- https://github.com/advisories/GHSA-2326-hx7g-3m9r Advisory
- https://github.com/apache/mina-sshd/commit/315739e4e9d1dc7a4ff32ea64936982ed0b73e76
- https://github.com/apache/mina-sshd/commit/6b0fd46f64bcb75eeeee31d65f10242660aad7c1
- https://github.com/apache/mina-sshd/commit/7b2c781640a7a78a9455b86593a1f63c9e8cab92
- https://github.com/apache/mina-sshd/issues/445 issue-trackingIssue Tracking
- https://github.com/apache/mina-sshd/pull/449
- https://github.com/apache/mina-sshd/releases/tag/sshd-2.12.0
- https://lists.apache.org/thread/vwf1ot8wx1njyy8n19j5j2tcnjnozt3b vendor-advisoryMailing ListVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-41909
- https://security.netapp.com/advisory/ntap-20241011-0006
- https://www.cve.org/CVERecord?id=CVE-2024-41909
Change history (0)
No recorded changes yet.