Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-29425

Опубликовано: 13 апр. 2021
Источник: ubuntu
Приоритет: medium
EPSS Средний
CVSS2: 5.8
CVSS3: 4.8

Описание

In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to construct a path value.

РелизСтатусПримечание
bionic

released

2.6-2ubuntu0.18.04.1
devel

not-affected

2.8.0-1
esm-apps-legacy/xenial

needed

esm-apps/bionic

released

2.6-2ubuntu0.18.04.1
esm-apps/focal

released

2.6-2ubuntu0.20.04.1
esm-apps/jammy

not-affected

2.8.0-1
esm-apps/noble

not-affected

2.8.0-1
esm-apps/resolute

not-affected

2.8.0-1
esm-apps/xenial

ignored

end of ESM support, was needed
esm-infra-legacy/trusty

released

2.4-2ubuntu0.1~esm1

Показывать по

EPSS

Процентиль: 95%
0.10233
Средний

5.8 Medium

CVSS2

4.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.8
redhat
больше 5 лет назад

In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to construct a path value.

CVSS3: 4.8
nvd
больше 5 лет назад

In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to construct a path value.

CVSS3: 4.8
debian
больше 5 лет назад

In Apache Commons IO before 2.7, When invoking the method FileNameUtil ...

suse-cvrf
больше 5 лет назад

Security update for apache-commons-io

suse-cvrf
больше 5 лет назад

Security update for apache-commons-io

EPSS

Процентиль: 95%
0.10233
Средний

5.8 Medium

CVSS2

4.8 Medium

CVSS3