CVE-2020-15152: Server-Side Request Forgery (SSRF)
(updated )
ftp-srv is vulnerable to Server-Side Request Forgery. The PORT
command allows arbitrary IPs which can be used to cause the server to make a connection elsewhere. A possible workaround is blocking the PORT through the configuration.
References
Detect and mitigate CVE-2020-15152 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →