CVE-2021-31810
MEDIUMRuby < 2.6.7, 2.7.x < 2.7.3, 3.x < 3.0.1 - Information Disclosure via FTP PASV Response
Title source: llmDescription
An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, and 3.x through 3.0.1. A malicious FTP server can use the PASV response to trick Net::FTP into connecting back to a given IP address and port. This potentially makes curl extract information about services that are otherwise private and not disclosed (e.g., the attacker can conduct port scans and service banner extractions).
References (8)
Core 8
Core References
Mailing List, Third Party Advisory vendor-advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MWXHK5UUHVSHF7HTHMX6JY3WXDVNIHSL/
Mailing List, Third Party Advisory mailing-list
https://lists.debian.org/debian-lts-announce/2021/10/msg00009.html
Mailing List mailing-list
https://lists.debian.org/debian-lts-announce/2023/04/msg00033.html
Third Party Advisory vendor-advisory
https://security.gentoo.org/glsa/202401-27
Exploit, Patch, Third Party Advisory
https://hackerone.com/reports/1145454
Third Party Advisory
https://security.netapp.com/advisory/ntap-20210917-0001/
Patch, Third Party Advisory
https://www.oracle.com/security-alerts/cpuapr2022.html
Scores
CVSS v3
5.8
EPSS
0.0065
EPSS Percentile
71.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Details
Status
published
Products (3)
debian/debian_linux
9.0
oracle/jd_edwards_enterpriseone_tools
< 9.2.6.1
ruby-lang/ruby
< 2.6.7
Published
Jul 13, 2021
Tracked Since
Feb 18, 2026