← לוח פגיעויות

CVE-2021-29425

בינונית 4.8

תיאור (מקור, אנגלית)

In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to construct a path value.

מדדים

CVSS 3.1
4.8 (MEDIUM) מקור הציון: NVD CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
EPSS — סבירות ניצול
11% (אחוזון 100) נכון ל-8/10/2026
CWE
CWE-20, CWE-22

מוצרים מושפעים

apache: commons io; debian: debian linux; oracle: access manager; oracle: agile engineering data management; oracle: agile product lifecycle management; oracle: application performance management; oracle: application testing suite; oracle: banking apis; oracle: banking digital experience; oracle: banking enterprise default management; oracle: banking enterprise default managment; oracle: banking party management; oracle: banking platform; oracle: blockchain platform; oracle: commerce guided search

קישורים