{ "schema_version": "1.4.0", "id": "GHSA-f8pr-x4hc-3mhf", "modified": "2022-05-24T17:07:08Z", "published": "2022-05-24T17:07:08Z", "aliases": [ "CVE-2020-5221" ], "details": "In uftpd before 2.11, it is possible for an unauthenticated user to perform a directory traversal attack using multiple different FTP commands and read and write to arbitrary locations on the filesystem due to the lack of a well-written chroot jail in compose_abspath(). This has been fixed in version 2.11", "severity": [], "affected": [], "references": [ { "type": "WEB", "url": "https://github.com/troglobit/uftpd/security/advisories/GHSA-wmx8-v7mx-6x9h" }, { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-5221" }, { "type": "WEB", "url": "https://github.com/troglobit/uftpd/commit/455b47d3756aed162d2d0ef7f40b549f3b5b30fe" } ], "database_specific": { "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2020-01-22T19:15:00Z" } }