VDB
Sign up
MEDIUM6.5

GHSA-cgp8-4m63-fhh5

Apache Commons Net vulnerable to information leakage via malicious server

Quick fix

GHSA-cgp8-4m63-fhh5 — commons-net:commons-net: upgrade to the fixed version with the command below.

# pom.xml: bump <version>3.9.0</version> for commons-net:commons-net

Details

Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host from PASV response by default. A malicious server can redirect the Commons Net code to use a different host, but the user has to connect to the malicious server in the first place. This may lead to leakage of information about services running on the private network of the client. The default in version 3.9.0 is now false to ignore such hosts, as cURL does. See https://issues.apache.org/jira/browse/NET-711.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/commons-net:commons-net
Introduced in: 0Fixed in: 3.9.0
Fix# pom.xml: bump <version>3.9.0</version> for commons-net:commons-net

References