PT-2021-6846 · Python+11 · Python+11
Confd0
·
Published
2021-04-05
·
Updated
2026-05-13
·
CVE-2021-4189
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Python (affected versions not specified)
Description
The issue is related to the FTP client library in Python, specifically in PASV (passive) mode, where the library trusts the host from the PASV response by default. This allows an attacker to set up a malicious FTP server that can trick FTP clients into connecting back to a given IP address and port, potentially leading to FTP client scanning ports.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Unchecked Return Value
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Astra Linux
Centos
Debian
Linuxmint
Python
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu