CVE-2021-31810
Last modified
CVE-2021-31810 is a medium-severity vulnerability rated 5.8/10 on the CVSS scale. An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, and 3.x through 3.0.1. A malicious FTP server can use the PASV response to trick Net::FTP into connecting back to a given IP address and port. EPSS estimates a 3.05% chance of exploitation in the next 30 days.
Description
An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, and 3.x through 3.0.1. A malicious FTP server can use the PASV response to trick Net::FTP into connecting back to a given IP address and port. This potentially makes curl extract information about services that are otherwise private and not disclosed (e.g., the attacker can conduct port scans and service banner extractions).
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ruby-Lang | Ruby | <= 2.6.7 |
| Ruby-Lang | Ruby | >= 2.7.0, <= 2.7.3 |
| Ruby-Lang | Ruby | >= 3.0.0, <= 3.0.1 |
| Debian | Debian Linux | 9.0 |
| Oracle | Jd Edwards Enterpriseone Tools | < 9.2.6.1 |
References
- https://hackerone.com/reports/1145454Exploit, Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/10/msg00009.htmlMailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20210917-0001/Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
- https://hackerone.com/reports/1145454Exploit, Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/10/msg00009.htmlMailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20210917-0001/Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-31810?
How severe is CVE-2021-31810?
How do I fix CVE-2021-31810?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-31804LeoCAD before 21.03 sometimes allows a use-after-free during…5.5
- CVE-2021-31805The fix issued for CVE-2020-17530 was incomplete. So from Ap…9.8
- CVE-2021-31806An issue was discovered in Squid before 4.15 and 5.x before …6.5
- CVE-2021-31807An issue was discovered in Squid before 4.15 and 5.x before …6.5
- CVE-2021-31808An issue was discovered in Squid before 4.15 and 5.x before …6.5
- CVE-2021-3181rfc822.c in Mutt through 2.0.4 allows remote attackers to ca…6.5
- CVE-2021-31811In Apache PDFBox, a carefully crafted PDF file can trigger a…5.5
- CVE-2021-31812In Apache PDFBox, a carefully crafted PDF file can trigger a…5.5
- CVE-2021-31813Zoho ManageEngine Applications Manager before 15130 is vulne…5.4
- CVE-2021-31814In Stormshield 1.1.0, and 2.1.0 through 2.9.0, an attacker c…6.1
- CVE-2021-31815GAEN (aka Google/Apple Exposure Notifications) through 2021-…3.3
- CVE-2021-31816When configuring Octopus Server if it is configured with an …7.5
Are you affected by CVE-2021-31810?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
