Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2021-37533— Apache Commons Net's FTP client trusts the host from PASV response by default

Quick assessment

Affected
Apache Software Foundation Apache Commons Net
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Apache Commons Net是美国阿帕奇(Apache)公司的一个库。实现了许多基本 Internet 协议的客户端。 Apache Commons Net 3.9.0之前版本存在输入验证错误漏洞,该漏洞源于Net 的 FTP 客户端默认信任来自 PASV 响应的主机,恶意服务器可以重定向 Commons Net 代码以使用不同的主机,但用户必须首先连接到恶意服务器,导致有关在客户端专用网络上运行的服务的信息泄露。

AI Predicted 6.5 Difficulty: Easy EPSS 2.05% · P80

Possible ATT&CK Techniques 1 AI

T1071 · Application Layer Protocol
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2021-37533

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Apache Commons Net's FTP client trusts the host from PASV response by default
Source: CVE Program / CVE List V5
Vulnerability Description
Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host from PASV response by default. A malicious server can redirect the Commons Net code to use a different host, but the user has to connect to the malicious server in the first place. This may lead to leakage of information about services running on the private network of the client. The default in version 3.9.0 is now false to ignore such hosts, as cURL does. See https://issues.apache.org/jira/browse/NET-711.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
输入验证不恰当
Source: CVE Program / CVE List V5
Vulnerability Title
Apache Commons Net 输入验证错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Apache Commons Net是美国阿帕奇(Apache)公司的一个库。实现了许多基本 Internet 协议的客户端。 Apache Commons Net 3.9.0之前版本存在输入验证错误漏洞,该漏洞源于Net 的 FTP 客户端默认信任来自 PASV 响应的主机,恶意服务器可以重定向 Commons Net 代码以使用不同的主机,但用户必须首先连接到恶意服务器,导致有关在客户端专用网络上运行的服务的信息泄露。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Apache Software Foundation Apache Commons Net Apache Commons Net ~ 3.9.0 -

II. Public POCs for CVE-2021-37533

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2021-37533

请登录查看更多情报信息。

Vendor Advisories for CVE-2021-37533 (1)

Mailing List Discussions for CVE-2021-37533 (3)

IV. Related Vulnerabilities

V. Comments for CVE-2021-37533

No comments yet


Leave a comment