CyberRota Analysis
AI-GeneratedThe Apache MINA SSHD library's SFTP client is vulnerable to memory exhaustion due to improper handling of unsolicited replies from servers, which can lead to significant resource depletion. This issue affects versions 0.9.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5, making it critical for organizations using these versions to prioritize upgrading to 2.20.0 or 3.0.0-M6 to mitigate potential denial-of-service attacks. Users of the affected SFTP client should address this vulnerability promptly to ensure system stability and security.
Original NVD Description
Possible memory exhaustion in SFTP clients (DefaultSftpClient) in component sshd-sftp in Apache MINA SSHD versions 0.9.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is a Java library for client-side and server-side SSH. The sshd-sftp component provides support for SFTP. The SFTP client implementation, when receiving a reply, did not check that this reply corresponded to a request sent earlier. Unsolicited replies would be stored but never consumed. A malicious server could keep sending unsolicited replies until available memory in the client was exhausted. Users are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue.