At line 1 changed 2 lines |
__April 19th, 2024 - CVE-2024-4040\\ |
CrushFTP v11 versions below 11.1 have a vulnerability where users can escape their VFS and download system files. This has been patched in v11.1.0. Customers using a [DMZ] in front of their main CrushFTP instance are partially protected with its protocol translation system it utilizes. A DMZ however does not fully protect you and you must update immediately. (CREDIT:Simon Garrelou, of Airbus CERT)__\\ |
__November 11th, 2024 - (CVE N/A)\\ |
V10 versions below 10.8.3 and V11 versions below 11.2.3 are vulnerable to a password reset email exploit. If an end user clicks the link, their account is compromised. |
(CREDIT: Stratascale Cyber Research Unit)__\\ |
Once you update you must configure your allowed email reset URL domains.\\ |
v10:Preferences, WebInterface, MiniURL: Set an allowed list of domains, comma separated.\\ |
v11:Preferneces, WebInterface, Login Page: Set a domain pattern that is not just * as * is no longer allowed.\\ |
---- |
April 19th, 2024 - CVE-2024-4040\\ |
CrushFTP v11 versions below 11.1 have a vulnerability where users can escape their VFS and download system files. This has been patched in v11.1.0. Customers using a [DMZ] in front of their main CrushFTP instance are partially protected with its protocol translation system it utilizes. A DMZ however does not fully protect you and you must update immediately. (CREDIT:Simon Garrelou, of Airbus CERT)\\ |
---- |
At line 5 changed 5 lines |
•If I'm on v10.7.1...do I need to upgrade to v11? No, just update v10 to v10.7.1.\\ |
•If I'm on v10.6.1, or v10.3, or v10.5.5, am I vulnerable? Yes! Update immediately to 10.7.1.\\ |
•Can you tell me how I can check if I have been exploited? Not really..the nature of this was common words that could be in your log already. So there is no silver bullet search term to check for. Looking for "<INCLUDE" is an indicator.\\ |
•If I have a DMZ am I safe? NO! As of April 22, we have changed our opinion on this. A DMZ does not fully protect you.\\ |
•If I only have my SFTP port exposed to the internet but not any web ports...am I safe? Yes, this exploit specifically works with the WebInterface port.\\ |
•If I'm on v10.8.3+...do I need to upgrade to v11? No, 10.7.1+ are safe.\\ |
•If I'm on v10.6.1, or v10.3, or v10.5.5, am I vulnerable? Yes! Update immediately to 10.8.3+ or v11.2.3+.\\ |