-
Notifications
You must be signed in to change notification settings - Fork 612
Closed
Description
This library have a hight security problem, exposed in this spanish blog "https://www.fwhibbit.es/0day-senor-tiname-el-sobrero-rfi-por-ssh"
SCP accept any name, and could produce a RFI in scenario like this
https://youtu.be/gKnDuLy4bwk
There is no check of the file name at "https://github.com/hierynomus/sshj/blob/master/src/main/java/net/schmizz/sshj/xfer/scp/SCPDownloadClient.java#L156" and "
| throws IOException { |
Metadata
Metadata
Assignees
Labels
No labels