Possible limited path traversal vulnerabily in Apache Commons IO
Summary
| CVE | CVE-2021-29425 |
|---|---|
| State | PUBLISHED |
| Assigner | apache |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-04-13 07:15:12 UTC |
| Updated | 2026-08-25 16:28:27 UTC |
| Description | In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to construct a path value. |
Risk And Classification
Primary CVSS: v3.1 4.8 MEDIUM from [email protected]
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
EPSS: 0.102330000 probability, percentile 0.953130000 (date 2026-08-25)
Problem Types: CWE-20 | CWE-22 | CWE-20 CWE-20 Improper Input Validation
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 4.8 | MEDIUM | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N |
| 2.0 | [email protected] | Primary | 5.8 | AV:N/AC:M/Au:N/C:P/I:P/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
HighPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
LowIntegrity
LowAvailability
NoneCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:P/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Commons Io | 2.2 | - | All | All |
| Application | Apache | Commons Io | 2.3 | - | All | All |
| Application | Apache | Commons Io | 2.4 | - | All | All |
| Application | Apache | Commons Io | 2.5 | - | All | All |
| Application | Apache | Commons Io | 2.6 | - | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Application | Netapp | Active Iq Unified Manager | - | All | All | All |
| Application | Netapp | Active Iq Unified Manager | - | All | All | All |
| Application | Netapp | Active Iq Unified Manager | - | All | All | All |
| Application | Oracle | Access Manager | 11.1.2.3.0 | All | All | All |
| Application | Oracle | Access Manager | 12.2.1.3.0 | All | All | All |
| Application | Oracle | Access Manager | 12.2.1.4.0 | All | All | All |
| Application | Oracle | Agile Engineering Data Management | 6.2.1.0 | All | All | All |
| Application | Oracle | Agile Product Lifecycle Management | 9.3.6 | All | All | All |
| Application | Oracle | Application Performance Management | 13.4.1.0 | All | All | All |
| Application | Oracle | Application Performance Management | 13.5.1.0 | All | All | All |
| Application | Oracle | Application Testing Suite | 13.3.0.1 | All | All | All |
| Application | Oracle | Banking Apis | 18.1 | All | All | All |
| Application | Oracle | Banking Apis | 18.2 | All | All | All |
| Application | Oracle | Banking Apis | 18.3 | All | All | All |
| Application | Oracle | Banking Apis | 19.1 | All | All | All |
| Application | Oracle | Banking Apis | 19.2 | All | All | All |
| Application | Oracle | Banking Apis | 20.1 | All | All | All |
| Application | Oracle | Banking Apis | 21.1 | All | All | All |
| Application | Oracle | Banking Digital Experience | 17.2 | All | All | All |
| Application | Oracle | Banking Digital Experience | 18.1 | All | All | All |
| Application | Oracle | Banking Digital Experience | 18.3 | All | All | All |
| Application | Oracle | Banking Digital Experience | 19.1 | All | All | All |
| Application | Oracle | Banking Digital Experience | 19.2 | All | All | All |
| Application | Oracle | Banking Digital Experience | 20.1 | All | All | All |
| Application | Oracle | Banking Digital Experience | 21.1 | All | All | All |
| Application | Oracle | Banking Enterprise Default Management | 2.10.0 | All | All | All |
| Application | Oracle | Banking Enterprise Default Management | 2.12.0 | All | All | All |
| Application | Oracle | Banking Enterprise Default Management | 2.6.2 | All | All | All |
| Application | Oracle | Banking Enterprise Default Management | 2.7.0 | All | All | All |
| Application | Oracle | Banking Enterprise Default Management | 2.7.1 | All | All | All |
| Application | Oracle | Banking Enterprise Default Managment | All | All | All | All |
| Application | Oracle | Banking Party Management | 2.7.0 | All | All | All |
| Application | Oracle | Banking Platform | 2.6.2 | All | All | All |
| Application | Oracle | Banking Platform | 2.7.0 | All | All | All |
| Application | Oracle | Banking Platform | 2.7.1 | All | All | All |
| Application | Oracle | Banking Platform | All | All | All | All |
| Application | Oracle | Blockchain Platform | All | All | All | All |
| Application | Oracle | Commerce Guided Search | 11.3.2 | All | All | All |
| Application | Oracle | Communications Application Session Controller | 3.9.0 | All | All | All |
| Application | Oracle | Communications Billing And Revenue Management Elastic Charging Engine | 11.3 | All | All | All |
| Application | Oracle | Communications Billing And Revenue Management Elastic Charging Engine | 12.0 | All | All | All |
| Application | Oracle | Communications Cloud Native Core Network Repository Function | 1.14.0 | All | All | All |
| Application | Oracle | Communications Cloud Native Core Policy | 1.14.0 | All | All | All |
| Application | Oracle | Communications Cloud Native Core Unified Data Repository | 1.4.0 | All | All | All |
| Application | Oracle | Communications Contacts Server | 8.0.0.6.0 | All | All | All |
| Application | Oracle | Communications Converged Application Server - Service Controller | 6.2 | All | All | All |
| Application | Oracle | Communications Convergence | 3.0.2.2.0 | All | All | All |
| Application | Oracle | Communications Design Studio | 7.3.5 | All | All | All |
| Application | Oracle | Communications Design Studio | All | All | All | All |
| Application | Oracle | Communications Diameter Intelligence Hub | All | All | All | All |
| Application | Oracle | Communications Diameter Intelligence Hub | All | All | All | All |
| Application | Oracle | Communications Interactive Session Recorder | 6.3 | All | All | All |
| Application | Oracle | Communications Interactive Session Recorder | 6.4 | All | All | All |
| Application | Oracle | Communications Offline Mediation Controller | 12.0.0.3 | All | All | All |
| Application | Oracle | Communications Order And Service Management | 7.3 | All | All | All |
| Application | Oracle | Communications Order And Service Management | 7.4 | All | All | All |
| Application | Oracle | Communications Policy Management | 12.5.0.0.0 | All | All | All |
| Application | Oracle | Communications Pricing Design Center | 12.0.0.4.0 | All | All | All |
| Application | Oracle | Communications Pricing Design Center | 12.0.0.5.0 | All | All | All |
| Application | Oracle | Communications Service Broker | 6.2 | All | All | All |
| Application | Oracle | Enterprise Communications Broker | 3.3 | All | All | All |
| Application | Oracle | Enterprise Session Border Controller | 8.4 | All | All | All |
| Application | Oracle | Enterprise Session Border Controller | 9.0 | All | All | All |
| Application | Oracle | Financial Services Analytical Applications Infrastructure | All | All | All | All |
| Application | Oracle | Financial Services Model Management And Governance | All | All | All | All |
| Application | Oracle | Flexcube Core Banking | 11.10.0 | All | All | All |
| Application | Oracle | Flexcube Core Banking | 5.2.0 | All | All | All |
| Application | Oracle | Flexcube Core Banking | All | All | All | All |
| Application | Oracle | Fusion Middleware Mapviewer | 12.2.1.4.0 | All | All | All |
| Application | Oracle | Healthcare Data Repository | 8.1.0 | All | All | All |
| Application | Oracle | Health Sciences Data Management Workbench | 2.5.2.1 | All | All | All |
| Application | Oracle | Health Sciences Data Management Workbench | 3.0.0.0 | All | All | All |
| Application | Oracle | Health Sciences Information Manager | All | All | All | All |
| Application | Oracle | Helidon | 1.4.7 | All | All | All |
| Application | Oracle | Helidon | 2.2.0 | All | All | All |
| Application | Oracle | Insurance Policy Administration | 11.0.2 | All | All | All |
| Application | Oracle | Insurance Policy Administration | 11.1.0 | All | All | All |
| Application | Oracle | Insurance Policy Administration | 11.2.8 | All | All | All |
| Application | Oracle | Insurance Policy Administration | 11.3.0 | All | All | All |
| Application | Oracle | Insurance Policy Administration | 11.3.1 | All | All | All |
| Application | Oracle | Insurance Rules Palette | 11.0.2 | All | All | All |
| Application | Oracle | Insurance Rules Palette | 11.1.0 | All | All | All |
| Application | Oracle | Insurance Rules Palette | 11.2.8 | All | All | All |
| Application | Oracle | Insurance Rules Palette | 11.3.0 | All | All | All |
| Application | Oracle | Insurance Rules Palette | 11.3.1 | All | All | All |
| Application | Oracle | Oss Support Tools | All | All | All | All |
| Application | Oracle | Primavera Unifier | 18.8 | All | All | All |
| Application | Oracle | Primavera Unifier | 19.12 | All | All | All |
| Application | Oracle | Primavera Unifier | 20.12 | All | All | All |
| Application | Oracle | Primavera Unifier | 21.12 | All | All | All |
| Application | Oracle | Primavera Unifier | All | All | All | All |
| Application | Oracle | Real User Experience Insight | 13.4.1.0 | All | All | All |
| Application | Oracle | Real User Experience Insight | 13.5.1.0 | All | All | All |
| Application | Oracle | Rest Data Services | All | All | All | All |
| Application | Oracle | Rest Data Services | 21.3 | All | All | All |
| Application | Oracle | Retail Assortment Planning | 16.0.3 | All | All | All |
| Application | Oracle | Retail Integration Bus | 13.0 | All | All | All |
| Application | Oracle | Retail Integration Bus | 14.1.3.0 | All | All | All |
| Application | Oracle | Retail Integration Bus | 14.1.3.2 | All | All | All |
| Application | Oracle | Retail Integration Bus | 15.0.3.1 | All | All | All |
| Application | Oracle | Retail Integration Bus | 19.0.0 | All | All | All |
| Application | Oracle | Retail Integration Bus | 19.0.1 | All | All | All |
| Application | Oracle | Retail Integration Bus | All | All | All | All |
| Application | Oracle | Retail Merchandising System | 16.0.3 | All | All | All |
| Application | Oracle | Retail Merchandising System | 19.0.1 | All | All | All |
| Application | Oracle | Retail Order Broker | 16.0 | All | All | All |
| Application | Oracle | Retail Order Broker | 18.0 | All | All | All |
| Application | Oracle | Retail Order Broker | 19.1 | All | All | All |
| Application | Oracle | Retail Pricing | 19.0.1 | All | All | All |
| Application | Oracle | Retail Service Backbone | 14.1.3.0 | All | All | All |
| Application | Oracle | Retail Service Backbone | 14.1.3.2 | All | All | All |
| Application | Oracle | Retail Service Backbone | 15.0.3.1 | All | All | All |
| Application | Oracle | Retail Service Backbone | 19.0.0 | All | All | All |
| Application | Oracle | Retail Service Backbone | 19.0.1 | All | All | All |
| Application | Oracle | Retail Service Backbone | All | All | All | All |
| Application | Oracle | Retail Size Profile Optimization | 16.0.3 | All | All | All |
| Application | Oracle | Retail Xstore Point Of Service | 17.0.4 | All | All | All |
| Application | Oracle | Retail Xstore Point Of Service | 18.0.3 | All | All | All |
| Application | Oracle | Retail Xstore Point Of Service | 19.0.2 | All | All | All |
| Application | Oracle | Retail Xstore Point Of Service | 20.0.1 | All | All | All |
| Application | Oracle | Solaris Cluster | 4.0 | All | All | All |
| Application | Oracle | Utilities Testing Accelerator | 6.0.0.1.1 | All | All | All |
| Application | Oracle | Utilities Testing Accelerator | 6.0.0.2.2 | All | All | All |
| Application | Oracle | Utilities Testing Accelerator | 6.0.0.3.1 | All | All | All |
| Application | Oracle | Webcenter Portal | 12.2.1.3.0 | All | All | All |
| Application | Oracle | Webcenter Portal | 12.2.1.4.0 | All | All | All |
| Application | Oracle | Weblogic Server | 12.1.3.0.0 | All | All | All |
| Application | Oracle | Weblogic Server | 12.2.1.3.0 | All | All | All |
| Application | Oracle | Weblogic Server | 12.2.1.4.0 | All | All | All |
| Application | Oracle | Weblogic Server | 14.1.1.0.0 | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Apache Software Foundation | Apache Commons IO | affected Apache Commons IO 2.2 | Not specified |
| CNA | Apache Software Foundation | Apache Commons IO | affected Apache Commons IO 2.3 | Not specified |
| CNA | Apache Software Foundation | Apache Commons IO | affected Apache Commons IO 2.4 | Not specified |
| CNA | Apache Software Foundation | Apache Commons IO | affected Apache Commons IO 2.5 | Not specified |
| CNA | Apache Software Foundation | Apache Commons IO | affected Apache Commons IO 2.6 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| lists.apache.org/thread.html/r345330b7858304938b7b8029d02537a116d75265a598c98f... | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| lists.apache.org/thread.html/rfd01af05babc95b8949e6d8ea78d9834699e1b06981040dd... | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| Oracle Critical Patch Update Advisory - April 2022 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | Patch, Third Party Advisory |
| lists.apache.org/thread.html/ra8ef65aedc086d2d3d21492b4c08ae0eb8a3a42cc52e29ba... | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| lists.apache.org/thread.html/r8efcbabde973ea72f5e0933adc48ef1425db5cde850bf641... | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| Oracle Critical Patch Update Advisory - October 2021 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | Third Party Advisory |
| lists.apache.org/thread.html/rc2dd3204260e9227a67253ef68b6f1599446005bfa0e1ddc... | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| lists.apache.org/thread.html/rd09d4ab3e32e4b3a480e2ff6ff118712981ca82e817f28f2... | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| lists.apache.org/thread.html/r27b1eedda37468256c4bb768fde1e8b79b37ec975cbbfd0d... | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| lists.apache.org/thread.html/rc5f3df5316c5237b78a3dff5ab95b311ad08e61d418cd992... | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| lists.apache.org/thread.html/r4050f9f6b42ebfa47a98cbdee4aabed4bb5fb8093db7dbb8... | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| CVE-2021-29425 Apache Commons IO Vulnerability in NetApp Products | NetApp Product Security | af854a3a-2127-422b-91ae-364da2661108 | security.netapp.com | Third Party Advisory |
| [IO-556] Unexpected behavior of FileNameUtils.normalize may lead to limited path traversal vulnerabilies - ASF JIRA | af854a3a-2127-422b-91ae-364da2661108 | issues.apache.org | Exploit, Issue Tracking, Vendor Advisory |
| lists.apache.org/thread.html/r523a6ffad58f71c4f3761e3cee72df878e48cdc89ebdce93... | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| lists.apache.org/thread.html/rca71a10ca533eb9bfac2d590533f02e6fb9064d3b6aa3ec9... | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| lists.apache.org/thread.html/r92ea904f4bae190b03bd42a4355ce3c2fbe8f36ab673e03f... | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| lists.apache.org/thread.html/rfa2f08b7c0caf80ca9f4a18bd875918fdd4e894e2ea47942... | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| lists.apache.org/thread.html/rbebd3e19651baa7a4a5503a9901c95989df9d40602c8e35c... | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| Oracle Critical Patch Update Advisory - January 2022 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | Patch, Third Party Advisory |
| Oracle Critical Patch Update Advisory - July 2022 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | Patch, Third Party Advisory |
| lists.apache.org/thread.html/r20416f39ca7f7344e7d76fe4d7063bb1d91ad106926626e7... | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| lists.apache.org/thread.html/r2df50af2641d38f432ef025cd2ba5858215cc0cf3fc10396... | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| lists.apache.org/thread.html/rad4ae544747df32ccd58fff5a86cd556640396aeb161aa71... | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| [SECURITY] [DLA 2741-1] commons-io security update | af854a3a-2127-422b-91ae-364da2661108 | lists.debian.org | Mailing List, Third Party Advisory |
| lists.apache.org/thread.html/r2bc986a070457daca457a54fe71ee09d2584c24dc262336c... | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| lists.apache.org/thread.html/r462db908acc1e37c455e11b1a25992b81efd18e641e7e0ce... | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| lists.apache.org/thread.html/rfcd2c649c205f12b72dde044f905903460669a220a2eb7e1... | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| lists.apache.org/thread.html/red3aea910403d8620c73e1c7b9c9b145798d0469eb3298a7... | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| lists.apache.org/thread.html/raa053846cae9d497606027816ae87b4e002b2e0eb66cb0de... | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| lists.apache.org/thread.html/r1c2f4683c35696cf6f863e3c107e37ec41305b1930dd40c1... | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| lists.apache.org/thread.html/r5149f78be265be69d34eacb4e4b0fc7c9c697bcdfa91a1c1... | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| lists.apache.org/thread.html/r0d73e2071d1f1afe1a15da14c5b6feb2cf17e3871168d5a3... | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| lists.apache.org/thread.html/r47ab6f68cbba8e730f42c4ea752f3a44eb95fb09064070f2... | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| lists.apache.org/thread.html/r808be7d93b17a7055c1981a8453ae5f0d0fce5855407793c... | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| lists.apache.org/thread.html/r8569a41d565ca880a4dee0e645dad1cd17ab4a92e68055ad... | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| lists.apache.org/thread.html/r873d5ddafc0a68fd999725e559776dc4971d1ab39c0f5cc8... | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| lists.apache.org/thread.html/r2345b49dbffa8a5c3c589c082fe39228a2c1d14f11b96c52... | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| lists.apache.org/thread.html/rc65f9bc679feffe4589ea0981ee98bc0af9139470f077a91... | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| lists.apache.org/thread.html/r86528f4b7d222aed7891e7ac03d69a0db2a2dfa17b86ac34... | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| lists.apache.org/thread.html/r477c285126ada5c3b47946bb702cb222ac4e7fd3100c8549... | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | Mailing List, Vendor Advisory |
| lists.apache.org/thread.html/r8bfc7235e6b39d90e6f446325a5a44c3e9e50da18860fdab... | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| lists.apache.org/thread.html/r2721aba31a8562639c4b937150897e24f78f747cdbda8641... | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| lists.apache.org/thread.html/r01b4a1fcdf3311c936ce33d75a9398b6c255f00c1a2f312a... | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| lists.apache.org/thread.html/re41e9967bee064e7369411c28f0f5b2ad28b8334907c9c62... | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| lists.apache.org/thread.html/r0bfa8f7921abdfae788b1f076a12f73a92c93cc0a6e1083b... | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| lists.apache.org/thread.html/rc10fa20ef4d13cbf6ebe0b06b5edb95466a1424a9b767307... | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
Workarounds
CNA: Neither the method in question (FileNameUtils.normalize) nor any methods, that invoke it, do actually access any files. There's only a string returned, from which a path can be constructed. In other words, a possible workaround would be not passing any unsafe input to FileNameUtils.normalize.
CNA: Upgrade to Apache Commons IO 2.7, or later, where the same method returns the value null, as an indication of "invalid input".
Legacy QID Mappings
- 150500 Oracle WebLogic Server Multiple Vulnerabilities (JAN2022)
- 150588 Oracle WebLogic Server Multiple Vulnerabilities (CPUOCT2022)
- 174935 SUSE Enterprise Linux Security Update for apache-commons-io (SUSE-SU-2021:1282-1)
- 174945 SUSE Enterprise Linux Security Update for apache-commons-io (SUSE-SU-2021:1315-1)
- 178758 Debian Security Update for commons-io (DLA 2741-1)
- 179750 Debian Security Update for commons-io (CVE-2021-29425)
- 198519 Ubuntu Security Notification for Apache Commons IO Vulnerability (USN-5095-1)
- 20276 Oracle Database 19c Critical OJVM Patch Update - October 2021
- 20290 Oracle Database 12.2.0.1 Critical OJVM Patch Update - October 2021
- 239608 Red Hat Update for Red Hat JBoss Enterprise Application Platform 7.3.9 (RHSA-2021:3468)
- 239609 Red Hat Update for Red Hat JBoss Enterprise Application Platform 7.3.9 (RHSA-2021:3467)
- 239610 Red Hat Update for Red Hat JBoss Enterprise Application Platform 7.3.9 (RHSA-2021:3466)
- 239652 Red Hat Update for Red Hat JBoss Enterprise Application Platform 7.4.1 (RHSA-2021:3658)
- 239653 Red Hat Update for Red Hat JBoss Enterprise Application Platform 7.4.1 (RHSA-2021:3656)
- 355318 Amazon Linux Security Advisory for apache-commons-io : ALAS2-2023-2059
- 375970 Oracle PeopleSoft Enterprise PeopleTools Product Multiple Vulnerabilities (CPUOCT2021)
- 378883 Splunk Enterprise August Third Party Package Updates (SVD-2023-0808)
- 750250 OpenSUSE Security Update for apache-commons-io (openSUSE-SU-2021:0605-1)
- 87467 Oracle WebLogic Server Multiple Vulnerabilities (CPUOCT2021)
- 87478 Oracle WebLogic Server Multiple Vulnerabilities (CPUJAN2022)
- 87542 Oracle WebLogic Server Multiple Vulnerabilities (CPUAPR2023)
- 980351 Java (maven) Security Update for commons-io:commons-io (GHSA-gwrp-pvrq-jmwv)