Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 9

Количество 9

github логотип

GHSA-gwrp-pvrq-jmwv

больше 5 лет назад

Path Traversal and Improper Input Validation in Apache Commons IO

CVSS3: 4.8
EPSS: Средний
ubuntu логотип

CVE-2021-29425

больше 5 лет назад

In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to construct a path value.

CVSS3: 4.8
EPSS: Средний
redhat логотип

CVE-2021-29425

больше 5 лет назад

In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to construct a path value.

CVSS3: 4.8
EPSS: Средний
nvd логотип

CVE-2021-29425

больше 5 лет назад

In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to construct a path value.

CVSS3: 4.8
EPSS: Средний
debian логотип

CVE-2021-29425

больше 5 лет назад

In Apache Commons IO before 2.7, When invoking the method FileNameUtil ...

CVSS3: 4.8
EPSS: Средний
suse-cvrf логотип

openSUSE-SU-2021:0605-1

больше 5 лет назад

Security update for apache-commons-io

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2021:1315-1

больше 5 лет назад

Security update for apache-commons-io

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2021:1282-1

больше 5 лет назад

Security update for apache-commons-io

EPSS: Средний
fstec логотип

BDU:2021-02220

больше 5 лет назад

Уязвимость метода FileNameUtils.normalize библиотеки Apache Commons IO, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 5.3
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-gwrp-pvrq-jmwv

Path Traversal and Improper Input Validation in Apache Commons IO

CVSS3: 4.8
10%
Средний
больше 5 лет назад
ubuntu логотип
CVE-2021-29425

In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to construct a path value.

CVSS3: 4.8
10%
Средний
больше 5 лет назад
redhat логотип
CVE-2021-29425

In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to construct a path value.

CVSS3: 4.8
10%
Средний
больше 5 лет назад
nvd логотип
CVE-2021-29425

In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to construct a path value.

CVSS3: 4.8
10%
Средний
больше 5 лет назад
debian логотип
CVE-2021-29425

In Apache Commons IO before 2.7, When invoking the method FileNameUtil ...

CVSS3: 4.8
10%
Средний
больше 5 лет назад
suse-cvrf логотип
openSUSE-SU-2021:0605-1

Security update for apache-commons-io

10%
Средний
больше 5 лет назад
suse-cvrf логотип
SUSE-SU-2021:1315-1

Security update for apache-commons-io

10%
Средний
больше 5 лет назад
suse-cvrf логотип
SUSE-SU-2021:1282-1

Security update for apache-commons-io

10%
Средний
больше 5 лет назад
fstec логотип
BDU:2021-02220

Уязвимость метода FileNameUtils.normalize библиотеки Apache Commons IO, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 5.3
10%
Средний
больше 5 лет назад

Уязвимостей на страницу

exploitDog - Комплексное решение для обнаружения, оценки и устранения уязвимостей.