Closed
Description
This library have a hight security problem, exposed in this spanish blog "https://www.fwhibbit.es/0day-senor-tiname-el-sobrero-rfi-por-ssh"
SCP accept any name, and could produce a RFI in scenario like this
There is no check of the file name at "https://github.com/hierynomus/sshj/blob/master/src/main/java/net/schmizz/sshj/xfer/scp/SCPDownloadClient.java#L156" and "
"Metadata
Metadata
Assignees
Labels
No labels