Bug 2487593 (CVE-2026-48858)
| Summary: | CVE-2026-48858 erlang: erlang-inets: erlang-ftp: Erlang/OTP ftp: Server-Side Request Forgery (SSRF) via unvalidated PASV response IP address | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | eglynn, jjoyce, jpretori, jschluet, lhh, mburns, mgarciac |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in Erlang/OTP's FTP (File Transfer Protocol) client, specifically within the ftp_internal module. A remote attacker, by operating a malicious or compromised FTP server, could exploit an unvalidated IP address in the server's passive mode (PASV) response. This vulnerability, known as Server-Side Request Forgery (SSRF), allows the attacker to redirect the client's data connection to an arbitrary internal host and port. This can lead to information disclosure from internal systems or the sending of sensitive data to unintended third-party hosts, enabling FTP bounce attacks.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2489552, 2489554 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-06-10 16:01:22 UTC
|