Giter VIP home page Giter VIP logo

Comments (9)

norrisjeremy avatar norrisjeremy commented on September 18, 2024 6

Hi @BernhardGruen,

Yes it is. We should be able to add support for the new "strict key exchange" OpenSSH added soon to help mitigate.

Thanks,
Jeremy

from jsch.

mwiede avatar mwiede commented on September 18, 2024 3

CVE-2023-48795 is fixed in version 0.2.15 or higher.

from jsch.

norrisjeremy avatar norrisjeremy commented on September 18, 2024 1

Hi @mohanchavata12,

That is a link to the original version of JSch that has been abandoned by the original developer.
The link for this fork of JSch is: https://mvnrepository.com/artifact/com.github.mwiede/jsch.

Thanks,
Jeremy

from jsch.

BernhardGruen avatar BernhardGruen commented on September 18, 2024

Hey @norrisjeremy

wow what a fast response - incredible.

Thank you so much for your answer. It seems the corresponding CVE https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-48795 does not yet mention jsch. Maybe you can add jsch to it after the fix is ready.

from jsch.

robtimus avatar robtimus commented on September 18, 2024

Snyk also doesn't recognize 0.2.15 as having fixed this: https://security.snyk.io/vuln/SNYK-JAVA-COMGITHUBMWIEDE-6130900

from jsch.

mwiede avatar mwiede commented on September 18, 2024

Snyk also doesn't recognize 0.2.15 as having fixed this: https://security.snyk.io/vuln/SNYK-JAVA-COMGITHUBMWIEDE-6130900

Snyk does not know 0.2.15, latest version in list is 0.2.14

from jsch.

mohanchavata12 avatar mohanchavata12 commented on September 18, 2024

Which versions of the jsch is vulnerable ? No indication of the Terrapin CVE on the component versions here
https://mvnrepository.com/artifact/com.jcraft/jsch

from jsch.

mohanchavata12 avatar mohanchavata12 commented on September 18, 2024

Thank you Jeremy for your quick response. As per the NVD, jsch before 0.2.15 is vulnerable to the Terrapin. There is no clear sign of the CVE 2023-48795 here- https://mvnrepository.com/artifact/com.github.mwiede/jsch or either in the Sync.

from jsch.

norrisjeremy avatar norrisjeremy commented on September 18, 2024

Hi @mohanchavata12,

We have no authority over how the https://mvnrepository.com/ is operated.
If this is especially important to you, I would recommend that you attempt to directly contact them.

Thanks,
Jeremy

from jsch.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.