Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Commons VFS.
The FtpFileObject class can throw an exception when a file is not found, revealing the original URI in its message, which may include a password. The fix is to mask the password in the exception message This issue affects Apache Commons VFS: before 2.10.0.
Users are recommended to upgrade to version 2.10.0, which fixes the issue.
CVSS Details
- CVSS 3.1 Base Score: 5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade apache-commons-vfs-examplesUpgrade apache-commons-vfsUpgrade apache-commons-vfs-antUpgrade apache-commons-vfs-javadoc | Apr 17, 2025 | Mar 23, 2025 |
| Debian | — | Upgrade commons-vfs | Apr 4, 2025 | Mar 23, 2025 |
| Suse | — | Upgrade apache-commons-vfs2-antUpgrade apache-commons-vfs2-examplesUpgrade apache-commons-vfs2-javadocUpgrade apache-commons-vfs2 | Dec 5, 2025 | Mar 26, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub