Uploaded image for project: 'Commons Net'
  1. Commons Net
  2. NET-670

Apache Commons Net ftpClient.java changeWorkingDirectory() Function CRLF Injection Remote Command Execution

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Critical
    • Resolution: Not A Bug
    • 3.6
    • None
    • FTP
    • Patch, Important
    • BlackDuck Hub VulnDB 171100

    Description

      Per BlackDuck Hub VulnDB 171100

      Apache Commons Net contains a flaw in the changeWorkingDirectory() function in ftpClient.java that is triggered as user-supplied input is not properly sanitized. This may allow a remote attacker to use a newline character in a specially crafted string to execute arbitrary commands.

       

       

      Attachments

        Activity

          People

            Unassigned Unassigned
            hurstd David Hurst
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: