Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 7

Количество 7

fstec логотип

BDU:2023-00080

больше 4 лет назад

Уязвимость компонента FTP Client библиотеки Apache Commons Net, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации и осуществить CSRF-атаку

CVSS3: 6.5
EPSS: Низкий
redos логотип

ROS-20251216-7307

8 месяцев назад

Уязвимость apache-commons-net

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2021-37533

больше 3 лет назад

Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host from PASV response by default. A malicious server can redirect the Commons Net code to use a different host, but the user has to connect to the malicious server in the first place. This may lead to leakage of information about services running on the private network of the client. The default in version 3.9.0 is now false to ignore such hosts, as cURL does. See https://issues.apache.org/jira/browse/NET-711.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2021-37533

больше 3 лет назад

Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host from PASV response by default. A malicious server can redirect the Commons Net code to use a different host, but the user has to connect to the malicious server in the first place. This may lead to leakage of information about services running on the private network of the client. The default in version 3.9.0 is now false to ignore such hosts, as cURL does. See https://issues.apache.org/jira/browse/NET-711.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2021-37533

больше 3 лет назад

Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host from PASV response by default. A malicious server can redirect the Commons Net code to use a different host, but the user has to connect to the malicious server in the first place. This may lead to leakage of information about services running on the private network of the client. The default in version 3.9.0 is now false to ignore such hosts, as cURL does. See https://issues.apache.org/jira/browse/NET-711.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2021-37533

больше 3 лет назад

Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host fr ...

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-cgp8-4m63-fhh5

больше 3 лет назад

Apache Commons Net vulnerable to information leakage via malicious server

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2023-00080

Уязвимость компонента FTP Client библиотеки Apache Commons Net, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации и осуществить CSRF-атаку

CVSS3: 6.5
2%
Низкий
больше 4 лет назад
redos логотип
ROS-20251216-7307

Уязвимость apache-commons-net

CVSS3: 6.5
2%
Низкий
8 месяцев назад
ubuntu логотип
CVE-2021-37533

Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host from PASV response by default. A malicious server can redirect the Commons Net code to use a different host, but the user has to connect to the malicious server in the first place. This may lead to leakage of information about services running on the private network of the client. The default in version 3.9.0 is now false to ignore such hosts, as cURL does. See https://issues.apache.org/jira/browse/NET-711.

CVSS3: 6.5
2%
Низкий
больше 3 лет назад
redhat логотип
CVE-2021-37533

Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host from PASV response by default. A malicious server can redirect the Commons Net code to use a different host, but the user has to connect to the malicious server in the first place. This may lead to leakage of information about services running on the private network of the client. The default in version 3.9.0 is now false to ignore such hosts, as cURL does. See https://issues.apache.org/jira/browse/NET-711.

CVSS3: 6.5
2%
Низкий
больше 3 лет назад
nvd логотип
CVE-2021-37533

Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host from PASV response by default. A malicious server can redirect the Commons Net code to use a different host, but the user has to connect to the malicious server in the first place. This may lead to leakage of information about services running on the private network of the client. The default in version 3.9.0 is now false to ignore such hosts, as cURL does. See https://issues.apache.org/jira/browse/NET-711.

CVSS3: 6.5
2%
Низкий
больше 3 лет назад
debian логотип
CVE-2021-37533

Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host fr ...

CVSS3: 6.5
2%
Низкий
больше 3 лет назад
github логотип
GHSA-cgp8-4m63-fhh5

Apache Commons Net vulnerable to information leakage via malicious server

CVSS3: 6.5
2%
Низкий
больше 3 лет назад

Уязвимостей на страницу