VYPR

Commons Net

by Apache

CVEs (1)

  • CVE-2021-37533MedDec 3, 2022
    risk 0.35cvss 6.5epss 0.02

    Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host from PASV response by default. A malicious server can redirect the Commons Net code to use a different host, but the user has to connect to the malicious server in the first place. This may lead to leakage of…