CVE-2021-37533
Published on: Not Yet Published
Last Modified on: 01/10/2023 07:29:00 PM UTC
Certain versions of Commons Net from Apache contain the following vulnerability:
Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host from PASV response by default. A malicious server can redirect the Commons Net code to use a different host, but the user has to connect to the malicious server in the first place. This may lead to leakage of information about services running on the private network of the client. The default in version 3.9.0 is now false to ignore such hosts, as cURL does. See https://issues.apache.org/jira/browse/NET-711.
- CVE-2021-37533 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
- Affected Vendor/Software:
Apache Software Foundation - Apache Commons Net version < 3.9.0
CVSS3 Score: 6.5 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | REQUIRED |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | NONE | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
No Description Provided | lists.apache.org text/html |
![]() |
oss-security - CVE-2021-37533: Apache Commons Net's FTP client trusts the host from PASV response by default | www.openwall.com text/html |
![]() |
[SECURITY] [DLA 3251-1] libcommons-net-java security update | lists.debian.org text/html |
![]() |
Debian -- Security Information -- DSA-5307-1 libcommons-net-java | www.debian.org Depreciated Link text/html |
![]() |
Related QID Numbers
Exploit/POC from Github
Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host from PASV response by default. A malicious server…
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Apache | Commons Net | All | All | All | All |
Operating System | Debian | Debian Linux | 10.0 | All | All | All |
Operating System | Debian | Debian Linux | 11.0 | All | All | All |
- cpe:2.3:a:apache:commons_net:*:*:*:*:*:*:*:*:
- cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*:
- cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*:
Discovery Credit
Apache Commons would like to thank ZeddYu Lu for reporting this issue.
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2021-37533 : Prior to #Apache Commons Net 3.9.0, Net's FTP client trusts the host from PASV response by default… twitter.com/i/web/status/1… | 2022-12-03 15:05:06 |
![]() |
CVE-2021-37533 | 2022-12-03 16:38:44 |