5
CVSSv2

CVE-2020-15152

Published: 17/08/2020 Updated: 05/05/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.1 | Impact Score: 5.2 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

ftp-srv is an npm package which is a modern and extensible FTP server designed to be simple yet configurable. In ftp-srv prior to 2.19.6, 3.1.2, and 4.3.4 are vulnerable to Server-Side Request Forgery. The PORT command allows arbitrary IPs which can be used to cause the server to make a connection elsewhere. A possible workaround is blocking the PORT through the configuration. This issue is fixed in version2 2.19.6, 3.1.2, and 4.3.4. More information can be found on the linked advisory.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ftp-srv project ftp-srv