Логотип exploitDog
bind:"GHSA-cgp8-4m63-fhh5" OR bind:"CVE-2021-37533"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-cgp8-4m63-fhh5" OR bind:"CVE-2021-37533"

Количество 7

Количество 7

github логотип

GHSA-cgp8-4m63-fhh5

около 3 лет назад

Apache Commons Net vulnerable to information leakage via malicious server

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2021-37533

около 3 лет назад

Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host from PASV response by default. A malicious server can redirect the Commons Net code to use a different host, but the user has to connect to the malicious server in the first place. This may lead to leakage of information about services running on the private network of the client. The default in version 3.9.0 is now false to ignore such hosts, as cURL does. See https://issues.apache.org/jira/browse/NET-711.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2021-37533

почти 3 года назад

Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host from PASV response by default. A malicious server can redirect the Commons Net code to use a different host, but the user has to connect to the malicious server in the first place. This may lead to leakage of information about services running on the private network of the client. The default in version 3.9.0 is now false to ignore such hosts, as cURL does. See https://issues.apache.org/jira/browse/NET-711.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2021-37533

около 3 лет назад

Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host from PASV response by default. A malicious server can redirect the Commons Net code to use a different host, but the user has to connect to the malicious server in the first place. This may lead to leakage of information about services running on the private network of the client. The default in version 3.9.0 is now false to ignore such hosts, as cURL does. See https://issues.apache.org/jira/browse/NET-711.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2021-37533

около 3 лет назад

Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host fr ...

CVSS3: 6.5
EPSS: Низкий
fstec логотип

BDU:2023-00080

почти 4 года назад

Уязвимость компонента FTP Client библиотеки Apache Commons Net, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации и осуществить CSRF-атаку

CVSS3: 6.5
EPSS: Низкий
redos логотип

ROS-20251216-7307

около 1 месяца назад

Уязвимость apache-commons-net

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-cgp8-4m63-fhh5

Apache Commons Net vulnerable to information leakage via malicious server

CVSS3: 6.5
0%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2021-37533

Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host from PASV response by default. A malicious server can redirect the Commons Net code to use a different host, but the user has to connect to the malicious server in the first place. This may lead to leakage of information about services running on the private network of the client. The default in version 3.9.0 is now false to ignore such hosts, as cURL does. See https://issues.apache.org/jira/browse/NET-711.

CVSS3: 6.5
0%
Низкий
около 3 лет назад
redhat логотип
CVE-2021-37533

Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host from PASV response by default. A malicious server can redirect the Commons Net code to use a different host, but the user has to connect to the malicious server in the first place. This may lead to leakage of information about services running on the private network of the client. The default in version 3.9.0 is now false to ignore such hosts, as cURL does. See https://issues.apache.org/jira/browse/NET-711.

CVSS3: 6.5
0%
Низкий
почти 3 года назад
nvd логотип
CVE-2021-37533

Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host from PASV response by default. A malicious server can redirect the Commons Net code to use a different host, but the user has to connect to the malicious server in the first place. This may lead to leakage of information about services running on the private network of the client. The default in version 3.9.0 is now false to ignore such hosts, as cURL does. See https://issues.apache.org/jira/browse/NET-711.

CVSS3: 6.5
0%
Низкий
около 3 лет назад
debian логотип
CVE-2021-37533

Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host fr ...

CVSS3: 6.5
0%
Низкий
около 3 лет назад
fstec логотип
BDU:2023-00080

Уязвимость компонента FTP Client библиотеки Apache Commons Net, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации и осуществить CSRF-атаку

CVSS3: 6.5
0%
Низкий
почти 4 года назад
redos логотип
ROS-20251216-7307

Уязвимость apache-commons-net

CVSS3: 6.5
0%
Низкий
около 1 месяца назад

Уязвимостей на страницу