Vulnerabilities > Jcraft > Jsch > 0.1.37

DATE CVE VULNERABILITY TITLE RISK
2017-01-19 CVE-2016-5725 Path Traversal vulnerability in Jcraft Jsch
Directory traversal vulnerability in JCraft JSch before 0.1.54 on Windows, when the mode is ChannelSftp.OVERWRITE, allows remote SFTP servers to write to arbitrary files via a ..\ (dot dot backslash) in a response to a recursive GET command.
network
jcraft CWE-22
4.3