CVE-2020-15152 Information
Feb 14, 2021
cve
Description
ftp-srv versions 1.0.0 through 4.3.3 are vulnerable to Server-Side Request Forgery. The PORT command allows arbitrary IPs which can be used to cause the server to make a connection elsewhere. A possible workaround is blocking the PORT through the configuration. This issue is fixed in version 4.3.4. More information can be found on the linked advisory.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Reference
https://github.com/autovance/ftp-srv/commit/e449e75219d918c400dec65b4b0759f60476abca https://github.com/autovance/ftp-srv/security/advisories/GHSA-jw37-5gqr-cf9j https://www.npmjs.com/package/ftp-srv
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
NONE
Base Severity
9.1
Share on: