"-Synchronized-Data."

This commit is contained in:
CVE Team 2020-08-17 22:01:36 +00:00
parent fd12279484
commit e5969ecd6c
No known key found for this signature in database
GPG Key ID: 5708902F06FEF743
2 changed files with 6 additions and 1 deletions

View File

@ -68,6 +68,11 @@
"refsource": "CONFIRM",
"name": "https://security.netapp.com/advisory/ntap-20200320-0003/",
"url": "https://security.netapp.com/advisory/ntap-20200320-0003/"
},
{
"refsource": "CONFIRM",
"name": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00369.html",
"url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00369.html"
}
]
},

View File

@ -35,7 +35,7 @@
"description_data": [
{
"lang": "eng",
"value": "ftp-srv versions 1.0.0 through 4.3.3 are vulnerable to Server-Side Request Forgery. The PORT command allows arbitrary IPs which can be used to cause the server to make a connection elsewhere. A possible workaround is blocking the PORT through the configuration.\nThis issue is fixed in version 4.3.4. More information can be found on the linked advisory."
"value": "ftp-srv versions 1.0.0 through 4.3.3 are vulnerable to Server-Side Request Forgery. The PORT command allows arbitrary IPs which can be used to cause the server to make a connection elsewhere. A possible workaround is blocking the PORT through the configuration. This issue is fixed in version 4.3.4. More information can be found on the linked advisory."
}
]
},