CVE-2020-15152

CVE-2020-15152

ftp-srv versions 1.0.0 through 4.3.3 are vulnerable to Server-Side Request Forgery. The PORT command allows arbitrary IPs which can be used to cause the server to make a connection elsewhere. A possible workaround is blocking the PORT through the configuration. This issue is fixed in version 4.3.4. More information can be found on the linked advisory.

Source: CVE-2020-15152

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다