CVE-2021-29425
PoC —CVSS 3.1
4.8 medium
EPSS
10%p95
Published
()
Modified
Description
In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to construct a path value.
- Vendors
- apachedebianoraclenetapp
- Products
- commons io, debian linux, access manager, agile engineering data management, agile product lifecycle management, application performance management, application testing suite, banking apis, banking digital experience, banking enterprise default management, banking enterprise default managment, banking party management
- Weakness
- CWE-20, CWE-22
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.