Am I affected?

This record states its affected versions in a form that can't be compared automatically.

3.0.1 and up affected
5.5.1 not affected
5.2.11.6 not affected
5.1.4.14 not affected
every other version: unknown

Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Erlang OTP (ssh_sftpd module) allows Path Traversal.

This vulnerability is associated with program files lib/ssh/src/ssh_sftpd.erl and program routines ssh_sftpd:is_within_root/2.

The SFTP server uses string prefix matching via lists:prefix/2 rather than proper path component validation when checking if a path is within the configured root directory. This allows authenticated users to access sibling directories that share a common name prefix with the configured root directory. For example, if root is set to /home/user1, paths like /home/user10 or /home/user1_backup would incorrectly be considered within the root.

This issue affects OTP from OTP 17.0 before OTP 28.4.1, OTP 27.3.4.9 and OTP 26.2.5.18, corresponding to ssh from 3.0.1 before 5.5.1, 5.2.11.6 and 5.1.4.14.

Weaknesses & attack patterns

Weakness

CWE-22 · Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in catalog → MITRE ↗

Attack patterns

CAPEC-126 · Path Traversal MITRE ↗

Affected — Erlang / ssh Repository ↗

3.0.1 and up affected
5.5.1 not affected
5.2.11.6 not affected
5.1.4.14 not affected
every other version: unknown
default status unknown
cpe cpe:2.3:a:erlang:erlang/otp:*:*:*:*:*:*:*:*
modules · source files · routines
modules ssh_sftpd
source files src/ssh_sftpd.erl
routines ssh_sftpd:is_within_root/2

Affected — GitHub / erlang/otp Repository ↗

17.0 and up affected
28.4.1 not affected
27.3.4.9 not affected
26.2.5.18 not affected
84adefa and up affected
27688a8 not affected
9e0ac85 not affected
5ed603a not affected
every other version: unknown
default status unknown
cpe cpe:2.3:a:erlang:erlang/otp:*:*:*:*:*:*:*:*
modules · source files · routines
modules ssh_sftpd
source files lib/ssh/src/ssh_sftpd.erl
routines ssh_sftpd:is_within_root/2

Workarounds

  • Use OS-level chroot to run the Erlang VM/SFTP server process in an isolated filesystem environment.
  • Ensure that no sensitive or precious data is readable or writable by the OS user running the Erlang VM.
  • Ensure that the SFTP server port is not reachable from untrusted machines.
  • Use directory naming conventions that avoid common prefixes (e.g., /home/users/alice/ instead of /home/user1/).

Configurations

The SFTP subsystem must be enabled on the SSH server, the SSH port must be reachable by the attacker, and a root directory must be configured. This is the case when ssh_sftpd is included in the subsystems option with a root parameter and there exist sibling directories sharing the same name prefix as the root.

References

Credits

Luigino Camastra / Aisle Research Finder
Jakub Witczak Remediation developer
Michał Wąsowski Remediation reviewer

CVSS breakdown

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
« All CVEs