CVE-2025-30474
Apache Commons VFS: Failing to find an FTP file can reveal the URI's password in an error message
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Commons VFS. The FtpFileObject class can throw an exception when a file is not found, revealing the original URI in its message, which may include a password. The fix is to mask the password in the exception message
This issue affects Apache Commons VFS: before 2.10.0. Users are recommended to upgrade to version 2.10.0, which fixes the issue.
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Commons VFS. The FtpFileObject class can throw an exception when a file is not found, revealing the original URI in its message, which may include a password. The fix is to mask the password in the exception message This issue affects Apache Commons VFS: before 2.10.0. Users are recommended to upgrade to version 2.10.0, which fixes the issue.
This update for apache-commons-vfs2 fixes the following issues. Fixed possible path traversal issue when using NameScope.DESCENDENT Fixed information disclosure due to failing to find an FTP file reveal the URI's password in an error message. Upgrade to upstream version 2.10.0.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2025-02-28 CVE Published
- 2025-03-22 CVE Reserved
- 2025-04-01 CVE Updated
- 2025-05-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://issues.apache.org/jira/browse/VFS-169 | Related | |
http://www.openwall.com/lists/oss-security/2025/03/23/2 |
|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://lists.apache.org/thread/w6ztgnbk6ccry3470x191g3xwrpgy6f4 | 2025-03-23 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apache Software Foundation Search vendor "Apache Software Foundation" | Apache Commons VFS Search vendor "Apache Software Foundation" for product "Apache Commons VFS" | < 2.10.0 Search vendor "Apache Software Foundation" for product "Apache Commons VFS" and version " < 2.10.0" | en |
Affected
|