CVE-2021-29425
בינונית 4.8
תיאור (מקור, אנגלית)
In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to construct a path value.
מדדים
- CVSS 3.1
-
4.8 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N - EPSS — סבירות ניצול
- 11% (אחוזון 100) נכון ל-8/10/2026
- CWE
- CWE-20, CWE-22
מוצרים מושפעים
apache: commons io; debian: debian linux; oracle: access manager; oracle: agile engineering data management; oracle: agile product lifecycle management; oracle: application performance management; oracle: application testing suite; oracle: banking apis; oracle: banking digital experience; oracle: banking enterprise default management; oracle: banking enterprise default managment; oracle: banking party management; oracle: banking platform; oracle: blockchain platform; oracle: commerce guided search
קישורים
- https://issues.apache.org/jira/browse/IO-556 ExploitIssue TrackingVendor Advisory
- https://lists.apache.org/thread.html/rc359823b5500e9a9a2572678ddb8e01d3505a7ff… Mailing ListVendor Advisory
- https://issues.apache.org/jira/browse/IO-556 ExploitIssue TrackingVendor Advisory
- https://lists.apache.org/thread.html/rc359823b5500e9a9a2572678ddb8e01d3505a7ff… Mailing ListVendor Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.html PatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.html PatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.html PatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.html PatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.html PatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.html PatchThird Party Advisory