Medium severity6.5NVD Advisory· Published Dec 3, 2022· Updated Jun 17, 2026
CVE-2021-37533
CVE-2021-37533
Description
Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host from PASV response by default. A malicious server can redirect the Commons Net code to use a different host, but the user has to connect to the malicious server in the first place. This may lead to leakage of information about services running on the private network of the client. The default in version 3.9.0 is now false to ignore such hosts, as cURL does. See https://issues.apache.org/jira/browse/NET-711.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
commons-net:commons-netMaven | < 3.9.0 | 3.9.0 |
Affected products
7- osv-coords6 versionspkg:apk/chainguard/druidpkg:apk/chainguard/spark-3.5-scala-2.13pkg:apk/wolfi/druidpkg:apk/wolfi/spark-3.5-scala-2.13pkg:maven/commons-net/commons-netpkg:rpm/opensuse/apache-commons-net&distro=openSUSE%20Tumbleweed
< 37.0.0-r14+ 5 more
- (no CPE)range: < 37.0.0-r14
- (no CPE)range: < 3.5.7-r2
- (no CPE)range: < 37.0.0-r14
- (no CPE)range: < 3.5.7-r2
- (no CPE)range: < 3.9.0
- (no CPE)range: < 3.9.0-1.1
- Range: Apache Commons Net
Patches
Vulnerability mechanics
References
8- www.openwall.com/lists/oss-security/2022/12/03/1nvdIssue TrackingMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-cgp8-4m63-fhh5ghsaADVISORY
- lists.apache.org/thread/o6yn9r9x6s94v97264hmgol1sf48mvx7nvdIssue TrackingMailing ListVendor AdvisoryWEB
- lists.debian.org/debian-lts-announce/2022/12/msg00038.htmlnvdMailing ListThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2021-37533ghsaADVISORY
- www.debian.org/security/2022/dsa-5307nvdThird Party AdvisoryWEB
- github.com/apache/commons-net/commit/4fe1bae56e53f32756b1ca3296f3dd2c45e3e060ghsaWEB
- issues.apache.org/jira/browse/NET-711ghsaWEB
News mentions
0No linked articles in our index yet.