Lucene search

K
ubuntucveUbuntu.comUB:CVE-2021-37533
HistoryDec 03, 2022 - 12:00 a.m.

CVE-2021-37533

2022-12-0300:00:00
ubuntu.com
ubuntu.com
43
apache commons net
ftp client
host trust
vulnerability
information leakage
private network

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

0.003 Low

EPSS

Percentile

65.5%

Prior to Apache Commons Net 3.9.0, Net’s FTP client trusts the host from
PASV response by default. A malicious server can redirect the Commons Net
code to use a different host, but the user has to connect to the malicious
server in the first place. This may lead to leakage of information about
services running on the private network of the client. The default in
version 3.9.0 is now false to ignore such hosts, as cURL does. See
https://issues.apache.org/jira/browse/NET-711.

Bugs

OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchlibcommons-net-java< 3.6-1+deb11u1build0.18.04.1UNKNOWN
ubuntu20.04noarchlibcommons-net-java< 3.6-1+deb11u1build0.20.04.1UNKNOWN
ubuntu22.04noarchlibcommons-net-java< 3.6-1+deb11u1build0.22.04.1UNKNOWN
ubuntu22.10noarchlibcommons-net-java< 3.6-1+deb11u1build0.22.10.1UNKNOWN
ubuntu16.04noarchlibcommons-net-java< 3.4-2ubuntu2+esm1UNKNOWN

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

0.003 Low

EPSS

Percentile

65.5%