CVE-2017-14038: Medium severity CrushFTP Crushftp vulnerability
Published Aug 30, 2017
·Updated
CrushFTP before 7.8.0 and 8.x before 8.2.0 has a redirect vulnerability.
Affected Software
5 affected components
CrushFTP Crushftp<=7.7.0
CrushFTP Crushftp=8.0.2
CrushFTP Crushftp=8.0.3
CrushFTP Crushftp=8.0.4
CrushFTP Crushftp=8.1.0
Event History
Aug 30, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-14038?
CVE-2017-14038 is considered a high-severity vulnerability due to its potential for redirection attacks.
2
How do I fix CVE-2017-14038?
To fix CVE-2017-14038, upgrade to CrushFTP version 7.8.0 or later for the 7.x series, or 8.2.0 or later for the 8.x series.
3
What systems are affected by CVE-2017-14038?
CVE-2017-14038 affects CrushFTP versions prior to 7.8.0 and 8.x versions before 8.2.0.
4
What is the impact of CVE-2017-14038?
The impact of CVE-2017-14038 includes the possibility for attackers to redirect users to malicious sites.
5
Is there a workaround for CVE-2017-14038?
There are no documented workarounds for CVE-2017-14038; the recommended solution is to update the software.