Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-30474

Опубликовано: 23 мар. 2025
Источник: debian
EPSS Низкий

Описание

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Commons VFS. The FtpFileObject class can throw an exception when a file is not found, revealing the original URI in its message, which may include a password. The fix is to mask the password in the exception message This issue affects Apache Commons VFS: before 2.10.0. Users are recommended to upgrade to version 2.10.0, which fixes the issue.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
commons-vfsfixed2.0-1package

Примечания

  • https://www.openwall.com/lists/oss-security/2025/03/23/2

  • https://issues.apache.org/jira/browse/VFS-169

  • https://github.com/apache/commons-vfs/commit/9c22e5297c7cb9dd75adec7ebcba06448e993bd8 (VFS-2.0-RC1)

EPSS

Процентиль: 45%
0.00224
Низкий

Связанные уязвимости

CVSS3: 5
ubuntu
11 месяцев назад

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Commons VFS. The FtpFileObject class can throw an exception when a file is not found, revealing the original URI in its message, which may include a password. The fix is to mask the password in the exception message This issue affects Apache Commons VFS: before 2.10.0. Users are recommended to upgrade to version 2.10.0, which fixes the issue.

CVSS3: 5
nvd
11 месяцев назад

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Commons VFS. The FtpFileObject class can throw an exception when a file is not found, revealing the original URI in its message, which may include a password. The fix is to mask the password in the exception message This issue affects Apache Commons VFS: before 2.10.0. Users are recommended to upgrade to version 2.10.0, which fixes the issue.

github
11 месяцев назад

Apache Commons VFS Exposure of Sensitive Information to an Unauthorized Actor

CVSS3: 7.5
fstec
11 месяцев назад

Уязвимость класса FtpFileObject единого API для доступа к различным файловым системам Apache Commons VFS (Virtual File System), позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

suse-cvrf
11 месяцев назад

Security update for apache-commons-vfs2

EPSS

Процентиль: 45%
0.00224
Низкий