basic-ftp is vulnerable to Server-Side Request Forgery (SSRF)
70
High Risk
The basic-ftp client opens passive-mode IPv4 data connections using the host and port returned in PASV responses. When separate transfer hosts are allowed, a malicious FTP server can supply an arbitrary address and port so the client connects elsewhere on the network. Before the fix this behavior was enabled by default, enabling FTP bounce and SSRF-style probing of internal hosts and services. The fix disables separate transfer hosts by default and rejects PASV responses whose host does not match the control connection.
You are affected if you are using a version that falls within the vulnerable range.
basic-ftp is vulnerable to Server-Side Request Forgery (SSRF) in versions 0.0.1 - 5.3.1.
Upgrade the basic-ftp library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant