Skip to content

ftplib should not use the host from the PASV response #87451

Description

@ricexdream
BPO 43285
Nosy @gpshead, @giampaolo, @ned-deily, @miss-islington
PRs
  • bpo-43285 Make ftplib not trust the PASV response. #24838
  • [3.9] bpo-43285 Make ftplib not trust the PASV response. (GH-24838) #24880
  • [3.8] bpo-43285 Make ftplib not trust the PASV response. (GH-24838) #24881
  • [3.6] bpo-43285 Make ftplib not trust the PASV response. (GH-24838) (GH-24881) #24882
  • [3.7] bpo-43285 Make ftplib not trust the PASV response. (GH-24838) (GH-24881) #24883
  • bpo-43285: Whats New entry for 3.8.9. #24886
  • bpo-43285: Add a What's New entry for 3.9.3. #24887
  • [3.9] bpo-43285: Add a What's New entry for 3.9.3. #24888
  • [3.8] bpo-43285: Whats New entry for 3.8.9. #24889
  • Note: these values reflect the state of the issue at the time it was migrated and might not reflect the current state.

    Show more details

    GitHub fields:

    assignee = None
    closed_at = <Date 2021-03-16.21:54:25.203>
    created_at = <Date 2021-02-21.11:49:34.689>
    labels = ['type-security', '3.7', 'library', 'release-blocker']
    title = 'ftplib should not use the host from the PASV response'
    updated_at = <Date 2021-03-16.21:54:25.202>
    user = 'https://bugs.python.org/ricexdream'

    bugs.python.org fields:

    activity = <Date 2021-03-16.21:54:25.202>
    actor = 'ned.deily'
    assignee = 'none'
    closed = True
    closed_date = <Date 2021-03-16.21:54:25.203>
    closer = 'ned.deily'
    components = ['Library (Lib)']
    creation = <Date 2021-02-21.11:49:34.689>
    creator = 'ricexdream'
    dependencies = []
    files = []
    hgrepos = []
    issue_num = 43285
    keywords = ['patch']
    message_count = 16.0
    messages = ['387455', '388267', '388602', '388610', '388757', '388761', '388762', '388763', '388768', '388777', '388812', '388813', '388815', '388882', '388885', '388891']
    nosy_count = 5.0
    nosy_names = ['gregory.p.smith', 'giampaolo.rodola', 'ned.deily', 'miss-islington', 'ricexdream']
    pr_nums = ['24838', '24880', '24881', '24882', '24883', '24886', '24887', '24888', '24889']
    priority = 'release blocker'
    resolution = 'fixed'
    stage = 'resolved'
    status = 'closed'
    superseder = None
    type = 'security'
    url = 'https://bugs.python.org/issue43285'
    versions = ['Python 3.6', 'Python 3.7']

    Linked PRs

    Activity

    1. ricexdream commented on Feb 21, 2021

      ricexdreammannequin
      MannequinAuthor

      Last year, curl had a security update for CVE-2020-8284. more info, see https://hackerone.com/reports/1040166

      The problem is ftp client trust the host from PASV response by default, A malicious server can trick ftp client into connecting
      back to a given IP address and port. This may make ftp client scan ports and extract service banner from private newwork.

      After test and read ftplib module(

      host, port = self.makepasv()
      ), I found ftplib has the same problem.

    2. added
      stdlibStandard Library Python modules in the Lib/ directory
      on Feb 21, 2021
    3. ricexdream commented on Mar 8, 2021

      ricexdreammannequin
      MannequinAuthor

      Any response here? If you need more information let me know.

    4. gpshead commented on Mar 13, 2021

      @gpshead
      Member

      Indeed, the host on that line there should just be ignored with the IP address of the original data connection used in its place.

      Your https://hackerone.com/reports/1040166 link provides plenty of information and likes to prior art mitigations other ftp clients including Firefox and Chrome well over a decade ago.

    5. self-assigned this
      on Mar 13, 2021
    6. 40 remaining items

    7. added 5 commits that reference this issue on May 13, 2026
    8. added a commit that references this issue on May 18, 2026
    9. added 2 commits that reference this issue on Jun 27, 2026
    10. added 4 commits that reference this issue on Sep 18, 2026
    11. added 3 commits that reference this issue on Oct 1, 2026
    Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

    Metadata

    Metadata

    Assignees

    No one assigned

      Labels

      3.7 (EOL)end of lifestdlibStandard Library Python modules in the Lib/ directorytype-securityA security issue

      Projects

      No projects

        Milestone

        No milestone

        Relationships

        None yet

        Development

        No branches or pull requests

        Issue actions