Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2021-29425

In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to construct a path value.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 46.5%
CVSS Severity
CVSS v3 Score 4.8
CVSS v2 Score 5.8
References
Products affected by CVE-2021-29425


Contact Us

Shodan ® - All rights reserved