Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-29425

Опубликовано: 12 апр. 2021
Источник: redhat
CVSS3: 4.8
EPSS Средний

Описание

In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to construct a path value.

Отчет

While the apache-commons-io package included in Red Hat Enterprise Linux 8 Maven App Stream contains the vulnerable code, it is not used in any way by Maven or other packages in this module. This package is not an API component of Maven, thus the affected code can not be reached in any supported scenario.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
A-MQ Clients 2commons-ioWill not fix
Red Hat BPM Suite 6commons-ioOut of support scope
Red Hat build of Quarkuscommons-ioNot affected
Red Hat Data Grid 8commons-ioWill not fix
Red Hat Enterprise Linux 7apache-commons-ioOut of support scope
Red Hat Enterprise Linux 8maven:3.5/apache-commons-ioNot affected
Red Hat Enterprise Linux 8maven:3.6/apache-commons-ioNot affected
Red Hat Enterprise Linux 9apache-commons-ioNot affected
Red Hat JBoss A-MQ 6commons-ioOut of support scope
Red Hat JBoss BRMS 6commons-ioOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=1948752apache-commons-io: Limited path traversal in Apache Commons IO 2.2 to 2.6

EPSS

Процентиль: 95%
0.10233
Средний

4.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.8
ubuntu
больше 5 лет назад

In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to construct a path value.

CVSS3: 4.8
nvd
больше 5 лет назад

In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to construct a path value.

CVSS3: 4.8
debian
больше 5 лет назад

In Apache Commons IO before 2.7, When invoking the method FileNameUtil ...

suse-cvrf
больше 5 лет назад

Security update for apache-commons-io

suse-cvrf
больше 5 лет назад

Security update for apache-commons-io

EPSS

Процентиль: 95%
0.10233
Средний

4.8 Medium

CVSS3

Уязвимость CVE-2021-29425