ZeroHour

CVE-2021-29425

PoC
CVSS 3.1
4.8 medium
EPSS
10%p95
Published
()
Modified
Description

In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to construct a path value.

Vendors
apachedebianoraclenetapp
Products
commons io, debian linux, access manager, agile engineering data management, agile product lifecycle management, application performance management, application testing suite, banking apis, banking digital experience, banking enterprise default management, banking enterprise default managment, banking party management
Weakness
CWE-20, CWE-22
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.