CVE-2021-29425
medium · 4.8In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to construct a path value.
4.8
CVSS
10.2%
EPSS (exploit prob.)
95th
EPSS percentile
2021-04-13
Published
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Weaknesses
CWE-20CWE-22
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| apache | commons_io | 2.2 |
| apache | commons_io | 2.3 |
| apache | commons_io | 2.4 |
| apache | commons_io | 2.5 |
| apache | commons_io | 2.6 |
| debian | debian_linux | 9.0 |
| oracle | access_manager | 11.1.2.3.0 |
| oracle | access_manager | 12.2.1.3.0 |
| oracle | access_manager | 12.2.1.4.0 |
| oracle | agile_engineering_data_management | 6.2.1.0 |
| oracle | agile_product_lifecycle_management | 9.3.6 |
| oracle | application_performance_management | 13.4.1.0 |
| oracle | application_performance_management | 13.5.1.0 |
| oracle | application_testing_suite | 13.3.0.1 |
| oracle | banking_apis | 18.1 |
| oracle | banking_apis | 18.2 |
| oracle | banking_apis | 18.3 |
| oracle | banking_apis | 19.1 |
| oracle | banking_apis | 19.2 |
| oracle | banking_apis | 20.1 |
| oracle | banking_apis | 21.1 |
| oracle | banking_digital_experience | 17.2 |
| oracle | banking_digital_experience | 18.1 |
| oracle | banking_digital_experience | 18.3 |
| oracle | banking_digital_experience | 19.1 |
| oracle | banking_digital_experience | 19.2 |
| oracle | banking_digital_experience | 20.1 |
| oracle | banking_digital_experience | 21.1 |
| oracle | banking_enterprise_default_management | 2.6.2 |
| oracle | banking_enterprise_default_management | 2.7.0 |
| oracle | banking_enterprise_default_management | 2.7.1 |
| oracle | banking_enterprise_default_management | 2.10.0 |
| oracle | banking_enterprise_default_management | 2.12.0 |
| oracle | banking_enterprise_default_managment | >= 2.3.0, <= 2.4.0 |
| oracle | banking_party_management | 2.7.0 |
| oracle | banking_platform | >= 2.3.0, <= 2.4.1 |
| oracle | banking_platform | 2.6.2 |
| oracle | banking_platform | 2.7.0 |
| oracle | banking_platform | 2.7.1 |
| oracle | blockchain_platform | < 21.1.2 |
Check a specific version with /api/v1/cve/match.
References
- https://issues.apache.org/jira/browse/IO-556
- https://lists.apache.org/thread.html/r01b4a1fcdf3311c936ce33d75a9398b6c255f00c1a2f312ac21effe1%40%3Cnotifications.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r0bfa8f7921abdfae788b1f076a12f73a92c93cc0a6e1083bce0027c5%40%3Cnotifications.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r0d73e2071d1f1afe1a15da14c5b6feb2cf17e3871168d5a3c8451436%40%3Ccommits.pulsar.apache.org%3E
- https://lists.apache.org/thread.html/r1c2f4683c35696cf6f863e3c107e37ec41305b1930dd40c17260de71%40%3Ccommits.pulsar.apache.org%3E
- https://lists.apache.org/thread.html/r20416f39ca7f7344e7d76fe4d7063bb1d91ad106926626e7e83fb346%40%3Cnotifications.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r2345b49dbffa8a5c3c589c082fe39228a2c1d14f11b96c523da701db%40%3Cnotifications.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r2721aba31a8562639c4b937150897e24f78f747cdbda8641c0f659fe%40%3Cusers.kafka.apache.org%3E
- https://lists.apache.org/thread.html/r27b1eedda37468256c4bb768fde1e8b79b37ec975cbbfd0d65a7ac34%40%3Cdev.myfaces.apache.org%3E
- https://lists.apache.org/thread.html/r2bc986a070457daca457a54fe71ee09d2584c24dc262336ca32b6a19%40%3Cdev.creadur.apache.org%3E
- https://lists.apache.org/thread.html/r2df50af2641d38f432ef025cd2ba5858215cc0cf3fc10396a674ad2e%40%3Cpluto-scm.portals.apache.org%3E
- https://lists.apache.org/thread.html/r345330b7858304938b7b8029d02537a116d75265a598c98fa333504a%40%3Cdev.creadur.apache.org%3E
- https://lists.apache.org/thread.html/r4050f9f6b42ebfa47a98cbdee4aabed4bb5fb8093db7dbb88faceba2%40%3Ccommits.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r462db908acc1e37c455e11b1a25992b81efd18e641e7e0ceb1b6e046%40%3Cnotifications.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r477c285126ada5c3b47946bb702cb222ac4e7fd3100c8549bdd6d3b2%40%3Cissues.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r47ab6f68cbba8e730f42c4ea752f3a44eb95fb09064070f2476bb401%40%3Cdev.creadur.apache.org%3E
- https://lists.apache.org/thread.html/r5149f78be265be69d34eacb4e4b0fc7c9c697bcdfa91a1c1658d717b%40%3Cissues.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r523a6ffad58f71c4f3761e3cee72df878e48cdc89ebdce933be1475c%40%3Cdev.creadur.apache.org%3E
- https://lists.apache.org/thread.html/r808be7d93b17a7055c1981a8453ae5f0d0fce5855407793c5d0ffffa%40%3Cuser.commons.apache.org%3E
- https://lists.apache.org/thread.html/r8569a41d565ca880a4dee0e645dad1cd17ab4a92e68055ad9ebb7375%40%3Cdev.creadur.apache.org%3E
- https://lists.apache.org/thread.html/r86528f4b7d222aed7891e7ac03d69a0db2a2dfa17b86ac3470d7f374%40%3Cnotifications.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r873d5ddafc0a68fd999725e559776dc4971d1ab39c0f5cc81bd9bc04%40%3Ccommits.pulsar.apache.org%3E
- https://lists.apache.org/thread.html/r8bfc7235e6b39d90e6f446325a5a44c3e9e50da18860fdabcee23e29%40%3Cissues.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r8efcbabde973ea72f5e0933adc48ef1425db5cde850bf641b3993f31%40%3Cdev.commons.apache.org%3E
- https://lists.apache.org/thread.html/r92ea904f4bae190b03bd42a4355ce3c2fbe8f36ab673e03f6ca3f9fa%40%3Cnotifications.zookeeper.apache.org%3E
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2021-29425