CVE-2021-37533
Apache Commons Net vulnerable to information leakage via malicious server
6.5
MEDIUM
CVSS 3.1
EPSS 0.25%
Description
Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host from PASV response by default. A malicious server can redirect the Commons Net code to use a different host, but the user has to connect to the malicious server in the first place. This may lead to leakage of information about services running on the private network of the client. The default in version 3.9.0 is now false to ignore such hosts, as cURL does. See https://issues.apache.org/jira/browse/NET-711.
How to fix CVE-2021-37533
To remediate CVE-2021-37533, upgrade the affected package to a fixed version below.
- —upgrade to 3.6-1+deb11u1 or later
- —upgrade to 3.6-1+deb10u1 or later
- —upgrade to 3.6-1+deb11u1 or later
- —upgrade to 3.9.0 or later
Is CVE-2021-37533 being exploited?
Low — EPSS is 0.2%, meaning exploitation activity has not been observed at scale.
Affected packages (4)
- from 0, < 3.6-1+deb11u1
- from 0, < 3.6-1+deb10u1
- from 0, < 3.6-1+deb11u1
- from 0, < 3.9.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |