{"id":"ECHO-221d-cef9-d3f8","summary":"Disputed by upstream and documented in netrw documentation.\nThe Netrw plugin stores credentials for an FTP session and\nsends those credentials when attempting to establish\nsubsequent FTP sessions to servers on different hosts, which\nallows remote FTP servers to obtain sensitive information in\nopportunistic circumstances by logging usernames and\npasswords.\nhttps://security-tracker.debian.org/tracker/CVE-2008-4677\n","modified":"2026-09-15T03:33:35.906299874Z","published":"2025-09-15T01:08:38.347675Z","withdrawn":"2026-04-12T13:58:47.682Z","upstream":["CVE-2008-4677"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2008-4677"}],"affected":[{"package":{"name":"vim","ecosystem":"Echo","purl":"pkg:deb/echo/vim"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:9.2.0218-1+e1"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-221d-cef9-d3f8.json"}}],"schema_version":"1.9.0"}