VYPR

JSch

by Jcraft

CVEs (1)

  • CVE-2016-5725MedJan 19, 2017
    risk 0.43cvss 5.9epss 0.24

    Directory traversal vulnerability in JCraft JSch before 0.1.54 on Windows, when the mode is ChannelSftp.OVERWRITE, allows remote SFTP servers to write to arbitrary files via a ..\ (dot dot backslash) in a response to a recursive GET command.