← volver
CVE-2021-29425CWE-20

Possible limited path traversal vulnerabily in Apache Commons IO

8Vexday Risk Score

Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.

ssvc Trackepss 10%
probabilidad de explotación
10%top 5% de las CVE
explotación observada
noninguna fuente lo reporta
In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to construct a path value.