CVE-2021-37533

Published on: Not Yet Published

Last Modified on: 01/10/2023 07:29:00 PM UTC

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Certain versions of Commons Net from Apache contain the following vulnerability:

Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host from PASV response by default. A malicious server can redirect the Commons Net code to use a different host, but the user has to connect to the malicious server in the first place. This may lead to leakage of information about services running on the private network of the client. The default in version 3.9.0 is now false to ignore such hosts, as cURL does. See https://issues.apache.org/jira/browse/NET-711.

  • CVE-2021-37533 has been assigned by URL Logo [email protected] to track the vulnerability - currently rated as MEDIUM severity.
  • Affected Vendor/Software: URL Logo Apache Software Foundation - Apache Commons Net version < 3.9.0

CVSS3 Score: 6.5 - MEDIUM

Attack
Vector
Attack
Complexity
Privileges
Required
User
Interaction
NETWORK LOW NONE REQUIRED
Scope Confidentiality
Impact
Integrity
Impact
Availability
Impact
UNCHANGED HIGH NONE NONE

CVE References

Description Tags Link
No Description Provided lists.apache.org
text/html
URL Logo MISC lists.apache.org/thread/o6yn9r9x6s94v97264hmgol1sf48mvx7
oss-security - CVE-2021-37533: Apache Commons Net's FTP client trusts the host from PASV response by default www.openwall.com
text/html
URL Logo MLIST [oss-security] 20221203 CVE-2021-37533: Apache Commons Net's FTP client trusts the host from PASV response by default
[SECURITY] [DLA 3251-1] libcommons-net-java security update lists.debian.org
text/html
URL Logo MLIST [debian-lts-announce] 20221229 [SECURITY] [DLA 3251-1] libcommons-net-java security update
Debian -- Security Information -- DSA-5307-1 libcommons-net-java www.debian.org
Depreciated Link
text/html
URL Logo DEBIAN DSA-5307

Related QID Numbers

  • 181450 Debian Security Update for libcommons-net-java (DLA 3251-1)
  • 181451 Debian Security Update for libcommons-net-java (DSA 5307-1)

Exploit/POC from Github

Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host from PASV response by default. A malicious server…

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
ApplicationApacheCommons NetAllAllAllAll
Operating
System
DebianDebian Linux10.0AllAllAll
Operating
System
DebianDebian Linux11.0AllAllAll
  • cpe:2.3:a:apache:commons_net:*:*:*:*:*:*:*:*:
  • cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*:
  • cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*:

Discovery Credit

Apache Commons would like to thank ZeddYu Lu for reporting this issue.

Social Mentions

Source Title Posted (UTC)
Twitter Icon @CVEreport CVE-2021-37533 : Prior to #Apache Commons Net 3.9.0, Net's FTP client trusts the host from PASV response by default… twitter.com/i/web/status/1… 2022-12-03 15:05:06
Reddit Logo Icon /r/netcve CVE-2021-37533 2022-12-03 16:38:44
© CVE.report 2023 Twitter Nitter Twitter Viewer |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

CVE.report and Source URL Uptime Status status.cve.report