PT-2025-12536 · Apache+2 · Apache Commons Vfs+2
Marek Šunda
·
Published
2025-03-23
·
Updated
2025-04-03
·
CVE-2025-30474
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Commons VFS versions prior to 2.10.0
Description
The issue is related to the exposure of sensitive information to an unauthorized actor in Apache Commons VFS. Specifically, the FtpFileObject class can throw an exception when a file is not found, revealing the original URI in its message, which may include a password.
Recommendations
For versions prior to 2.10.0, upgrade to version 2.10.0, which fixes the issue by masking the password in the exception message.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Commons Vfs
Debian
Suse