cbcvebase.
CVE-2021-37533
published 2022-12-03

CVE-2021-37533: Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host from PASV response by default. A malicious server can redirect the Commons Net code to use…

PriorityP335medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
1.86%
77.1th percentile
Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host from PASV response by default. A malicious server can redirect the Commons Net code to use a different host, but the user has to connect to the malicious server in the first place. This may lead to leakage of information about services running on the private network of the client. The default in version 3.9.0 is now false to ignore such hosts, as cURL does. See https://issues.apache.org/jira/browse/NET-711.

Affected

5 ranges
VendorProductVersion rangeFixed in
apachecommons_net< 3.9.03.9.0
apache_software_foundationapache_commons_net>= Apache Commons Net < 3.9.03.9.0
debiandebian_linux
debiandebian_linux
debianlibcommons-net-java< libcommons-net-java 3.9.0-1 (bookworm)libcommons-net-java 3.9.0-1 (bookworm)

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_oracle6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.