CVE-2021-37533
published 2022-12-03CVE-2021-37533: Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host from PASV response by default. A malicious server can redirect the Commons Net code to use…
PriorityP335medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
1.86%
77.1th percentile
Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host from PASV response by default. A malicious server can redirect the Commons Net code to use a different host, but the user has to connect to the malicious server in the first place. This may lead to leakage of information about services running on the private network of the client. The default in version 3.9.0 is now false to ignore such hosts, as cURL does. See https://issues.apache.org/jira/browse/NET-711.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | commons_net | < 3.9.0 | 3.9.0 |
| apache_software_foundation | apache_commons_net | >= Apache Commons Net < 3.9.0 | 3.9.0 |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libcommons-net-java | < libcommons-net-java 3.9.0-1 (bookworm) | libcommons-net-java 3.9.0-1 (bookworm) |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_oracle6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Communications Applications Risk Matrix: JCA Adaptor (Apache Commons Net) — CVE-2021-37533
vendor_oracle·2024-07-15·CVSS 6.5
CVE-2021-37533 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: JCA Adaptor (Apache Commons Net) — CVE-2021-37533
Oracle Oracle Communications Applications Risk Matrix: JCA Adaptor (Apache Commons Net) vulnerability
CVE: CVE-2021-37533
CVSS: 6.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2024 (JUL 2024)
Oracle
Oracle Oracle Communications Applications Risk Matrix: General (Apache Commons Net) — CVE-2021-37533
vendor_oracle·2024-04-15·CVSS 6.5
CVE-2021-37533 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: General (Apache Commons Net) — CVE-2021-37533
Oracle Oracle Communications Applications Risk Matrix: General (Apache Commons Net) vulnerability
CVE: CVE-2021-37533
CVSS: 6.5
Protocol: SFTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2024 (APR 2024)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Order and Service Management (Apache Commons Net) — CVE-2021-37533
vendor_oracle·2024-01-15·CVSS 6.5
CVE-2021-37533 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Order and Service Management (Apache Commons Net) — CVE-2021-37533
Oracle Oracle Communications Applications Risk Matrix: Order and Service Management (Apache Commons Net) vulnerability
CVE: CVE-2021-37533
CVSS: 6.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2024 (JAN 2024)
Oracle
Oracle Oracle Commerce Risk Matrix: Content Acquisition System (Apache Commons Net) — CVE-2021-37533
vendor_oracle·2023-10-15·CVSS 6.5
CVE-2021-37533 [MEDIUM] Oracle Oracle Commerce Risk Matrix: Content Acquisition System (Apache Commons Net) — CVE-2021-37533
Oracle Oracle Commerce Risk Matrix: Content Acquisition System (Apache Commons Net) vulnerability
CVE: CVE-2021-37533
CVSS: 6.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2023 (OCT 2023)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Other (Apache Commons Net) — CVE-2021-37533
vendor_oracle·2023-07-15·CVSS 6.5
CVE-2021-37533 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Other (Apache Commons Net) — CVE-2021-37533
Oracle Oracle Communications Applications Risk Matrix: Other (Apache Commons Net) vulnerability
CVE: CVE-2021-37533
CVSS: 6.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2023 (JUL 2023)
Ubuntu
Apache Commons Net vulnerability
vendor_ubuntu·2023-04-28
CVE-2021-37533 Apache Commons Net vulnerability
Title: Apache Commons Net vulnerability
Summary: Apache Commons Net could be made to expose sensitive information over the network.
ZeddYu Lu discovered that the FTP client from Apache Commons Net trusted
the host from PASV responses by default. A remote attacker with a
malicious FTP server could redirect the client to another server, which
could possibly result in leaked information about services running on the
private network of the client.
Instructions: In general, a standard system update will make all the necessary changes.
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Remote Diagnostic Agent (Apache Commons Net) — CVE-2021-37533
vendor_oracle·2023-04-15·CVSS 6.5
CVE-2021-37533 [MEDIUM] Oracle Oracle Fusion Middleware Risk Matrix: Remote Diagnostic Agent (Apache Commons Net) — CVE-2021-37533
Oracle Oracle Fusion Middleware Risk Matrix: Remote Diagnostic Agent (Apache Commons Net) vulnerability
CVE: CVE-2021-37533
CVSS: 6.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Red Hat
apache-commons-net: FTP client trusts the host from PASV response by default
vendor_redhat·2023-02-15·CVSS 6.5
CVE-2021-37533 [MEDIUM] CWE-20 apache-commons-net: FTP client trusts the host from PASV response by default
apache-commons-net: FTP client trusts the host from PASV response by default
Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host from PASV response by default. A malicious server can redirect the Commons Net code to use a different host, but the user has to connect to the malicious server in the first place. This may lead to leakage of information about services running on the private network of the client. The default in version 3.9.0 is now false to ignore such hosts, as cURL does. See https://issues.apache.org/jira/browse/NET-711.
A flaw was found in Apache Commons Net's FTP, where the client trusts the host from PASV response by default. A malicious server could redirect the Commons Net code to use a different host, but the user has to connect to the malicious server
Oracle
Oracle Oracle Support Tools Risk Matrix: Diagnostic Assistant (Apache Commons Net) — CVE-2021-37533
vendor_oracle·2023-01-15·CVSS 6.5
CVE-2021-37533 [MEDIUM] Oracle Oracle Support Tools Risk Matrix: Diagnostic Assistant (Apache Commons Net) — CVE-2021-37533
Oracle Oracle Support Tools Risk Matrix: Diagnostic Assistant (Apache Commons Net) vulnerability
CVE: CVE-2021-37533
CVSS: 6.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2023 (JAN 2023)
Debian
CVE-2021-37533: libcommons-net-java - Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host from PASV re...
vendor_debian·2021·CVSS 6.5
CVE-2021-37533 [MEDIUM] CVE-2021-37533: libcommons-net-java - Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host from PASV re...
Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host from PASV response by default. A malicious server can redirect the Commons Net code to use a different host, but the user has to connect to the malicious server in the first place. This may lead to leakage of information about services running on the private network of the client. The default in version 3.9.0 is now false to ignore such hosts, as cURL does. See https://issues.apache.org/jira/browse/NET-711.
Scope: local
bookworm: resolved (fixed in 3.9.0-1)
bullseye: resolved (fixed in 3.6-1+deb11u1)
forky: resolved (fixed in 3.9.0-1)
sid: resolved (fixed in 3.9.0-1)
trixie: resolved (fixed in 3.9.0-1)
OSV
Apache Commons Net vulnerable to information leakage via malicious server
osv·2022-12-03
CVE-2021-37533 [MEDIUM] Apache Commons Net vulnerable to information leakage via malicious server
Apache Commons Net vulnerable to information leakage via malicious server
Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host from PASV response by default. A malicious server can redirect the Commons Net code to use a different host, but the user has to connect to the malicious server in the first place. This may lead to leakage of information about services running on the private network of the client.
The default in version 3.9.0 is now false to ignore such hosts, as cURL does. See https://issues.apache.org/jira/browse/NET-711.
OSV
CVE-2021-37533: Prior to Apache Commons Net 3
osv·2022-12-03·CVSS 6.5
CVE-2021-37533 [MEDIUM] CVE-2021-37533: Prior to Apache Commons Net 3
Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host from PASV response by default. A malicious server can redirect the Commons Net code to use a different host, but the user has to connect to the malicious server in the first place. This may lead to leakage of information about services running on the private network of the client. The default in version 3.9.0 is now false to ignore such hosts, as cURL does. See https://issues.apache.org/jira/browse/NET-711.
GHSA
Apache Commons Net vulnerable to information leakage via malicious server
ghsa·2022-12-03
CVE-2021-37533 [MEDIUM] CWE-20 Apache Commons Net vulnerable to information leakage via malicious server
Apache Commons Net vulnerable to information leakage via malicious server
Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host from PASV response by default. A malicious server can redirect the Commons Net code to use a different host, but the user has to connect to the malicious server in the first place. This may lead to leakage of information about services running on the private network of the client.
The default in version 3.9.0 is now false to ignore such hosts, as cURL does. See https://issues.apache.org/jira/browse/NET-711.
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2022/12/03/1https://lists.apache.org/thread/o6yn9r9x6s94v97264hmgol1sf48mvx7https://lists.debian.org/debian-lts-announce/2022/12/msg00038.htmlhttps://www.debian.org/security/2022/dsa-5307http://www.openwall.com/lists/oss-security/2022/12/03/1https://lists.apache.org/thread/o6yn9r9x6s94v97264hmgol1sf48mvx7https://lists.debian.org/debian-lts-announce/2022/12/msg00038.htmlhttps://www.debian.org/security/2022/dsa-5307
2022-12-03
Published