Описание
In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to construct a path value.
Отчет
While the apache-commons-io package included in Red Hat Enterprise Linux 8 Maven App Stream contains the vulnerable code, it is not used in any way by Maven or other packages in this module. This package is not an API component of Maven, thus the affected code can not be reached in any supported scenario.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| A-MQ Clients 2 | commons-io | Will not fix | ||
| Red Hat BPM Suite 6 | commons-io | Out of support scope | ||
| Red Hat build of Quarkus | commons-io | Not affected | ||
| Red Hat Data Grid 8 | commons-io | Will not fix | ||
| Red Hat Enterprise Linux 7 | apache-commons-io | Out of support scope | ||
| Red Hat Enterprise Linux 8 | maven:3.5/apache-commons-io | Not affected | ||
| Red Hat Enterprise Linux 8 | maven:3.6/apache-commons-io | Not affected | ||
| Red Hat Enterprise Linux 9 | apache-commons-io | Not affected | ||
| Red Hat JBoss A-MQ 6 | commons-io | Out of support scope | ||
| Red Hat JBoss BRMS 6 | commons-io | Out of support scope |
Показывать по
Дополнительная информация
Статус:
EPSS
4.8 Medium
CVSS3
Связанные уязвимости
In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to construct a path value.
In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to construct a path value.
In Apache Commons IO before 2.7, When invoking the method FileNameUtil ...
EPSS
4.8 Medium
CVSS3