Lucene search

K
cve[email protected]CVE-2020-15152
HistoryAug 17, 2020 - 10:15 p.m.

CVE-2020-15152

2020-08-1722:15:12
CWE-918
web.nvd.nist.gov
29
2
ftp-srv
npm package
vulnerability
server-side request forgery
cve-2020-15152
security advisory

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

9.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

8.8 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

70.7%

ftp-srv is an npm package which is a modern and extensible FTP server designed to be simple yet configurable. In ftp-srv before versions 2.19.6, 3.1.2, and 4.3.4 are vulnerable to Server-Side Request Forgery. The PORT command allows arbitrary IPs which can be used to cause the server to make a connection elsewhere. A possible workaround is blocking the PORT through the configuration. This issue is fixed in version2 2.19.6, 3.1.2, and 4.3.4. More information can be found on the linked advisory.

Affected configurations

Vulners
NVD
Node
autovanceftp_srvRange1.0.02.19.6
OR
autovanceftp_srvRange3.0.03.1.2
OR
autovanceftp_srvRange4.0.04.3.4

CNA Affected

[
  {
    "product": "ftp-srv",
    "vendor": "autovance",
    "versions": [
      {
        "status": "affected",
        "version": ">= 1.0.0, < 2.19.6"
      },
      {
        "status": "affected",
        "version": ">= 3.0.0, < 3.1.2"
      },
      {
        "status": "affected",
        "version": ">= 4.0.0, < 4.3.4"
      }
    ]
  }
]

Social References

More

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

9.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

8.8 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

70.7%