Lucene search

K
ubuntuUbuntuUSN-6037-1
HistoryApr 28, 2023 - 12:00 a.m.

Apache Commons Net vulnerability

2023-04-2800:00:00
ubuntu.com
33
ubuntu 22.10
ubuntu 22.04 lts
ubuntu 20.04 lts
ubuntu 18.04 esm
ubuntu 16.04 esm
libcommons-net-java
ftp client
security vulnerability
remote attacker
malicious ftp server
leaked information

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

6.8 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

65.5%

Releases

  • Ubuntu 22.10
  • Ubuntu 22.04 LTS
  • Ubuntu 20.04 LTS
  • Ubuntu 18.04 ESM
  • Ubuntu 16.04 ESM

Packages

  • libcommons-net-java - Apache Commons Net - Java client API for basic Internet protocols

Details

ZeddYu Lu discovered that the FTP client from Apache Commons Net trusted
the host from PASV responses by default. A remote attacker with a
malicious FTP server could redirect the client to another server, which
could possibly result in leaked information about services running on the
private network of the client.

OSVersionArchitecturePackageVersionFilename
Ubuntu22.10noarchlibcommons-net-java< 3.6-1+deb11u1build0.22.10.1UNKNOWN
Ubuntu22.10noarchlibcommons-net-java-doc< 3.6-1+deb11u1build0.22.10.1UNKNOWN
Ubuntu22.04noarchlibcommons-net-java< 3.6-1+deb11u1build0.22.04.1UNKNOWN
Ubuntu22.04noarchlibcommons-net-java-doc< 3.6-1+deb11u1build0.22.04.1UNKNOWN
Ubuntu20.04noarchlibcommons-net-java< 3.6-1+deb11u1build0.20.04.1UNKNOWN
Ubuntu20.04noarchlibcommons-net-java-doc< 3.6-1+deb11u1build0.20.04.1UNKNOWN
Ubuntu18.04noarchlibcommons-net-java< 3.6-1+deb11u1build0.18.04.1UNKNOWN
Ubuntu18.04noarchlibcommons-net-java-doc< 3.6-1+deb11u1build0.18.04.1UNKNOWN
Ubuntu16.04noarchlibcommons-net-java< 3.4-2ubuntu2+esm1UNKNOWN
Ubuntu16.04noarchlibcommons-net-java< 3.4-2ubuntu2UNKNOWN
Rows per page:
1-10 of 111

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

6.8 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

65.5%