MEDIUM6.5
GHSA-cgp8-4m63-fhh5
Apache Commons Net vulnerable to information leakage via malicious server
Quick fix
GHSA-cgp8-4m63-fhh5 — commons-net:commons-net: upgrade to the fixed version with the command below.
# pom.xml: bump <version>3.9.0</version> for commons-net:commons-netDetails
Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host from PASV response by default. A malicious server can redirect the Commons Net code to use a different host, but the user has to connect to the malicious server in the first place. This may lead to leakage of information about services running on the private network of the client. The default in version 3.9.0 is now false to ignore such hosts, as cURL does. See https://issues.apache.org/jira/browse/NET-711.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/commons-net:commons-net
Introduced in:
0Fixed in: 3.9.0Fix
# pom.xml: bump <version>3.9.0</version> for commons-net:commons-netReferences
- https://nvd.nist.gov/vuln/detail/CVE-2021-37533[ADVISORY]
- https://github.com/apache/commons-net/commit/4fe1bae56e53f32756b1ca3296f3dd2c45e3e060[WEB]
- https://github.com/apache/commons-net[PACKAGE]
- https://issues.apache.org/jira/browse/NET-711[WEB]
- https://lists.apache.org/thread/o6yn9r9x6s94v97264hmgol1sf48mvx7[WEB]
- https://lists.debian.org/debian-lts-announce/2022/12/msg00038.html[WEB]
- https://www.debian.org/security/2022/dsa-5307[WEB]
- http://www.openwall.com/lists/oss-security/2022/12/03/1[WEB]