Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3936-3gx6-49c4

Опубликовано: 23 мар. 2025
Источник: github
Github: Прошло ревью
CVSS4: 6.9

Описание

Apache Commons VFS Exposure of Sensitive Information to an Unauthorized Actor

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Commons VFS.

The FtpFileObject class can throw an exception when a file is not found, revealing the original URI in its message, which may include a password. The fix is to mask the password in the exception message This issue affects Apache Commons VFS: before 2.10.0.

Users are recommended to upgrade to version 2.10.0, which fixes the issue.

Пакеты

Наименование

org.apache.commons:commons-vfs2

maven
Затронутые версииВерсия исправления

< 2.10.0

2.10.0

EPSS

Процентиль: 45%
0.00224
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 5
ubuntu
11 месяцев назад

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Commons VFS. The FtpFileObject class can throw an exception when a file is not found, revealing the original URI in its message, which may include a password. The fix is to mask the password in the exception message This issue affects Apache Commons VFS: before 2.10.0. Users are recommended to upgrade to version 2.10.0, which fixes the issue.

CVSS3: 5
nvd
11 месяцев назад

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Commons VFS. The FtpFileObject class can throw an exception when a file is not found, revealing the original URI in its message, which may include a password. The fix is to mask the password in the exception message This issue affects Apache Commons VFS: before 2.10.0. Users are recommended to upgrade to version 2.10.0, which fixes the issue.

CVSS3: 5
debian
11 месяцев назад

Exposure of Sensitive Information to an Unauthorized Actor vulnerabili ...

CVSS3: 7.5
fstec
11 месяцев назад

Уязвимость класса FtpFileObject единого API для доступа к различным файловым системам Apache Commons VFS (Virtual File System), позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

suse-cvrf
11 месяцев назад

Security update for apache-commons-vfs2

EPSS

Процентиль: 45%
0.00224
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-200