Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gh7c-cg3x-pmcr

Опубликовано: 01 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

pyftpdlib Use of Insufficiently Random Values of port selection on PASV command

pyftpdlib before 0.1.1 does not choose a random value for the port associated with the PASV command, which makes it easier for remote attackers to obtain potentially sensitive information about the number of in-progress data connections by reading the response to this command.

Пакеты

Наименование

pyftpdlib

pip
Затронутые версииВерсия исправления

< 0.1.1

0.1.1

EPSS

Процентиль: 45%
0.0025
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-330

Связанные уязвимости

nvd
около 15 лет назад

pyftpdlib before 0.1.1 does not choose a random value for the port associated with the PASV command, which makes it easier for remote attackers to obtain potentially sensitive information about the number of in-progress data connections by reading the response to this command.

debian
около 15 лет назад

pyftpdlib before 0.1.1 does not choose a random value for the port ass ...

EPSS

Процентиль: 45%
0.0025
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-330