VDB
RHSA-2023%3A3667
RHSA-2023%3A3667
PUBLISHED
CVSS 6.5 MEDIUM
A flaw was found in Apache Commons Net's FTP, where the client trusts the host from PASV response by default. A malicious server could redirect the Commons Net code to use a different host, but the user has to connect to the malicious server in the first place. This issue could lead to leakage of information about services running on the private network of the client.
Risk Scores
CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | RHINT Camel-Q 2.13.3 |
Timeline
- Jun 19, 2023 CVE Published
- Mar 21, 2026 CVE Updated
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2023:3667 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://access.redhat.com/security/cve/cve-2023-1436 advisory
- https://access.redhat.com/security/cve/cve-2021-37533 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2169924 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2182788 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_3667.json advisory
- https://access.redhat.com/security/cve/CVE-2021-37533 advisory
- https://www.cve.org/CVERecord?id=CVE-2021-37533 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-37533 advisory
- https://access.redhat.com/security/cve/CVE-2023-1436 advisory
- https://www.cve.org/CVERecord?id=CVE-2023-1436 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-1436 advisory
- https://research.jfrog.com/vulnerabilities/jettison-json-array-dos-xray-427911/ advisory