Impact
Improper validation of the FTP PASV reply address in mod_proxy_ftp for Apache HTTP Server versions up to 2.4.68 permits an untrusted upstream FTP server to instruct the forward proxy to open a data connection to any host specified in a crafted PASV response. This flaw is a CWE‑284 type access‑control weakness that can enable the attacker to cause the proxy to transmit data to a third‑party server, potentially exfiltrating data or serving as a foothold for subsequent attacks.
Affected Systems
Apache HTTP Server, all platforms, forward proxy configurations, versions through 2.4.68.
Risk and Exploitability
The vulnerability has no announced exploitation in the wild and is not listed in the CISA KEV catalog; EPSS is unavailable. However, it is exploitable when the attacker can control the FTP server the proxy connects to. By sending a forged PASV reply the attacker forces the proxy to initiate a TCP connection to an arbitrary host, which can be used for data exfiltration or to pivot to other systems. The CVSS score of 7.5 indicates a high severity level, and this capability to direct outbound connections to arbitrary addresses represents a significant risk in environments where the proxy has broad internet access.
OpenCVE Enrichment