Логотип exploitDog
bind:"CVE-2025-27553"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2025-27553"

Количество 8

Количество 8

ubuntu логотип

CVE-2025-27553

5 месяцев назад

Relative Path Traversal vulnerability in Apache Commons VFS before 2.10.0. The FileObject API in Commons VFS has a 'resolveFile' method that takes a 'scope' parameter. Specifying 'NameScope.DESCENDENT' promises that "an exception is thrown if the resolved file is not a descendent of the base file". However, when the path contains encoded ".." characters (for example, "%2E%2E/bar.txt"), it might return file objects that are not a descendent of the base file, without throwing an exception. This issue affects Apache Commons VFS: before 2.10.0. Users are recommended to upgrade to version 2.10.0, which fixes the issue.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2025-27553

5 месяцев назад

Relative Path Traversal vulnerability in Apache Commons VFS before 2.10.0. The FileObject API in Commons VFS has a 'resolveFile' method that takes a 'scope' parameter. Specifying 'NameScope.DESCENDENT' promises that "an exception is thrown if the resolved file is not a descendent of the base file". However, when the path contains encoded ".." characters (for example, "%2E%2E/bar.txt"), it might return file objects that are not a descendent of the base file, without throwing an exception. This issue affects Apache Commons VFS: before 2.10.0. Users are recommended to upgrade to version 2.10.0, which fixes the issue.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2025-27553

5 месяцев назад

Relative Path Traversal vulnerability in Apache Commons VFS before 2.10.0. The FileObject API in Commons VFS has a 'resolveFile' method that takes a 'scope' parameter. Specifying 'NameScope.DESCENDENT' promises that "an exception is thrown if the resolved file is not a descendent of the base file". However, when the path contains encoded ".." characters (for example, "%2E%2E/bar.txt"), it might return file objects that are not a descendent of the base file, without throwing an exception. This issue affects Apache Commons VFS: before 2.10.0. Users are recommended to upgrade to version 2.10.0, which fixes the issue.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2025-27553

5 месяцев назад

Relative Path Traversal vulnerability in Apache Commons VFS before 2.1 ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-9q4x-fr4m-jp86

5 месяцев назад

Apache Commons VFS Has Relative Path Traversal Vulnerability

CVSS3: 7.5
EPSS: Низкий
oracle-oval логотип

ELSA-2025-10548

20 дней назад

ELSA-2025-10548: apache-commons-vfs security update (MODERATE)

EPSS: Низкий
fstec логотип

BDU:2025-03216

5 месяцев назад

Уязвимость метода resolveFile единого API для доступа к различным файловым системам Apache Commons VFS (Virtual File System), позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:1022-1

5 месяцев назад

Security update for apache-commons-vfs2

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-27553

Relative Path Traversal vulnerability in Apache Commons VFS before 2.10.0. The FileObject API in Commons VFS has a 'resolveFile' method that takes a 'scope' parameter. Specifying 'NameScope.DESCENDENT' promises that "an exception is thrown if the resolved file is not a descendent of the base file". However, when the path contains encoded ".." characters (for example, "%2E%2E/bar.txt"), it might return file objects that are not a descendent of the base file, without throwing an exception. This issue affects Apache Commons VFS: before 2.10.0. Users are recommended to upgrade to version 2.10.0, which fixes the issue.

CVSS3: 7.5
0%
Низкий
5 месяцев назад
redhat логотип
CVE-2025-27553

Relative Path Traversal vulnerability in Apache Commons VFS before 2.10.0. The FileObject API in Commons VFS has a 'resolveFile' method that takes a 'scope' parameter. Specifying 'NameScope.DESCENDENT' promises that "an exception is thrown if the resolved file is not a descendent of the base file". However, when the path contains encoded ".." characters (for example, "%2E%2E/bar.txt"), it might return file objects that are not a descendent of the base file, without throwing an exception. This issue affects Apache Commons VFS: before 2.10.0. Users are recommended to upgrade to version 2.10.0, which fixes the issue.

CVSS3: 5.3
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2025-27553

Relative Path Traversal vulnerability in Apache Commons VFS before 2.10.0. The FileObject API in Commons VFS has a 'resolveFile' method that takes a 'scope' parameter. Specifying 'NameScope.DESCENDENT' promises that "an exception is thrown if the resolved file is not a descendent of the base file". However, when the path contains encoded ".." characters (for example, "%2E%2E/bar.txt"), it might return file objects that are not a descendent of the base file, without throwing an exception. This issue affects Apache Commons VFS: before 2.10.0. Users are recommended to upgrade to version 2.10.0, which fixes the issue.

CVSS3: 7.5
0%
Низкий
5 месяцев назад
debian логотип
CVE-2025-27553

Relative Path Traversal vulnerability in Apache Commons VFS before 2.1 ...

CVSS3: 7.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-9q4x-fr4m-jp86

Apache Commons VFS Has Relative Path Traversal Vulnerability

CVSS3: 7.5
0%
Низкий
5 месяцев назад
oracle-oval логотип
ELSA-2025-10548

ELSA-2025-10548: apache-commons-vfs security update (MODERATE)

20 дней назад
fstec логотип
BDU:2025-03216

Уязвимость метода resolveFile единого API для доступа к различным файловым системам Apache Commons VFS (Virtual File System), позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 7.5
0%
Низкий
5 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:1022-1

Security update for apache-commons-vfs2

5 месяцев назад

Уязвимостей на страницу