QID 980351

QID 980351: Java (maven) Security Update for commons-io:commons-io (GHSA-gwrp-pvrq-jmwv)

In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to construct a path value.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Medium - 4.8 severity.
  • CVSS V2 rated as Medium - 5.8 severity.
  • Solution
    Customers are advised to refer to GHSA-gwrp-pvrq-jmwv for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 980351

    Software Advisories
    Advisory ID Software Component Link
    GHSA-gwrp-pvrq-jmwv commons-io:commons-io URL Logo github.com/advisories/GHSA-gwrp-pvrq-jmwv