Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2025:1022-1

Опубликовано: 26 мар. 2025
Источник: suse-cvrf

Описание

Security update for apache-commons-vfs2

This update for apache-commons-vfs2 fixes the following issues:

  • CVE-2025-27553: Fixed possible path traversal issue when using NameScope.DESCENDENT (bsc#1239973)
  • CVE-2025-30474: Fixed information disclosure due to failing to find an FTP file reveal the URI's password in an error message (bsc#1239974)

Other fixes:

  • Upgrade to upstream version 2.10.0

Список пакетов

openSUSE Leap 15.6
apache-commons-vfs2-2.10.0-150200.3.3.1
apache-commons-vfs2-ant-2.10.0-150200.3.3.1
apache-commons-vfs2-examples-2.10.0-150200.3.3.1
apache-commons-vfs2-javadoc-2.10.0-150200.3.3.1

Описание

Relative Path Traversal vulnerability in Apache Commons VFS before 2.10.0. The FileObject API in Commons VFS has a 'resolveFile' method that takes a 'scope' parameter. Specifying 'NameScope.DESCENDENT' promises that "an exception is thrown if the resolved file is not a descendent of the base file". However, when the path contains encoded ".." characters (for example, "%2E%2E/bar.txt"), it might return file objects that are not a descendent of the base file, without throwing an exception. This issue affects Apache Commons VFS: before 2.10.0. Users are recommended to upgrade to version 2.10.0, which fixes the issue.


Затронутые продукты
openSUSE Leap 15.6:apache-commons-vfs2-2.10.0-150200.3.3.1
openSUSE Leap 15.6:apache-commons-vfs2-ant-2.10.0-150200.3.3.1
openSUSE Leap 15.6:apache-commons-vfs2-examples-2.10.0-150200.3.3.1
openSUSE Leap 15.6:apache-commons-vfs2-javadoc-2.10.0-150200.3.3.1

Ссылки

Описание

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Commons VFS. The FtpFileObject class can throw an exception when a file is not found, revealing the original URI in its message, which may include a password. The fix is to mask the password in the exception message This issue affects Apache Commons VFS: before 2.10.0. Users are recommended to upgrade to version 2.10.0, which fixes the issue.


Затронутые продукты
openSUSE Leap 15.6:apache-commons-vfs2-2.10.0-150200.3.3.1
openSUSE Leap 15.6:apache-commons-vfs2-ant-2.10.0-150200.3.3.1
openSUSE Leap 15.6:apache-commons-vfs2-examples-2.10.0-150200.3.3.1
openSUSE Leap 15.6:apache-commons-vfs2-javadoc-2.10.0-150200.3.3.1

Ссылки
Уязвимость SUSE-SU-2025:1022-1