CVE-2025-30474

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
23/03/2025
Last modified:
14/07/2025

Description

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Commons VFS.<br /> <br /> The FtpFileObject class can throw an exception when a file is not found, revealing the original URI in its message, which may include a password. The fix is to mask the password in the exception message<br /> This issue affects Apache Commons VFS: before 2.10.0.<br /> <br /> Users are recommended to upgrade to version 2.10.0, which fixes the issue.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:commons_vfs:*:*:*:*:*:*:*:* 2.10.0 (excluding)