PT-2026-86576 · Mwiede · Jsch
CVSS v3.1
3.7
Low
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
mwiede jsch versions prior to 2.28.6
Description
A security flaw exists in the
getRevokedKeys() function within the src/main/java/com/jcraft/jsch/KnownHosts.java file. A remote attacker can manipulate the known hosts argument to cause an improper check for certificate revocation. This attack is characterized by high complexity and is difficult to exploit.Recommendations
Upgrade to version 2.28.6.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jsch