At line 1 added 8 lines |
!!!__CrushFTP 11.0.0 to 11.3.0 are vulnerable. Update to 11.3.1+ immediately.__ |
!!!__CrushFTP 10.0.0 to 10.8.3 are vulnerable. Update to 10.8.4+ immediately.__ |
!!![Some guidance on detection and what to do if compromised...|Compromise] |
\\ |
|
!!!__Automated Updating__ |
Setting the flag "daily_check_and_auto_update_on_idle" to true in prefs.XML of CrushFTP v11.2.3_19+ will do automated daily checks and updates. |
|
At line 6 changed one line |
__November 11th, 2024 - (CVE-2024-53552 - CREDIT: Stratascale Cyber Research Unit)__\\ |
__March 21, 2025 - Unauthenticated HTTP(S) port access on CrushFTPv10/v11 (CVE: CVE-2025-31161)__\\ |
This issue affects both CrushFTP v10 and v11. The exploit does not work if you have the [DMZ] proxy instance of CrushFTP in place. The vulnerability was respnsibly disclosed, it is not being used actively in the wild that we know of, no further details will be given at this time. (CVE-2025-0282 appears to be a copycat CVE issued automatically by an unaffiliated company.)\\ |
10.8.4 and 11.3.1 were published on 3/21/2025 and your CrushFTP instances would have notified you within a day of the new version if you are not blocking access to our update servers. Staying up to date is critical on an internet facing server. |
---- |
November 11th, 2024 - (CVE-2024-53552 - CREDIT: Stratascale Cyber Research Unit)\\ |
At line 20 changed 2 lines |
•If I'm on v10.8.3+...do I need to upgrade to v11? No, 10.8.3+ are safe.\\ |
•If I'm on v10.6.1, or v10.3, or v10.5.5, am I vulnerable? Yes! Update immediately to 10.8.3+ or v11.2.3+.\\ |
•If I'm on v10.8.4+...do I need to upgrade to v11? No, 10.8.4+ are safe.\\ |
•If I'm on v10.6.1, or v10.3, or v10.5.5, am I vulnerable? Yes! Update immediately to 10.8.4+ or v11.3.1+.\\ |
At line 35 added one line |
---- |
At line 39 changed 2 lines |
|
|
\\ |
\\ |
!Fully manual offline update: |
In some rare scenarios when neither of the above methods work, like file permissions prevent consuming the update file or overwriting the necessary components by the updater. In such case: |
1.) Download CrushFTP11.zip from our download page. ([https://www.crushftp.com/early11/CrushFTP11.zip|https://www.crushftp.com/early11/CrushFTP11.zip])\\ |
2.) Unzip it to a temporary directory\\ |
3.) Stop the CrushFTP service |
4.) Copy over the installation the full content or just the __CrushFTP.jar__ file and the __plugins and WebInterface__ subdirectories as these are. Overwrite all when prompted.\\ |
5.) Start the Crush service. Once back on line, clear the browser cache or check with an incognito/private browser session. \\ |
\\ |
---- |
\\ |
At line 70 added one line |
---- |
At line 72 added one line |
---- |