In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to construct a path value.
CVSS Details
- CVSS 3.1 Base Score: 4.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | amazon-linux-ami-2-upgrade-apache-commons-ioamazon-linux-ami-2-upgrade-apache-commons-io-javadoc | Jun 6, 2023 | Apr 13, 2021 | |
| Debian | debian-upgrade-commons-io | Aug 16, 2021 | Apr 13, 2021 | |
| Oracle Weblogic | oracle-weblogic-jan-2022-cpu-12_1_3_0_0oracle-weblogic-jan-2022-cpu-12_2_1_3_0oracle-weblogic-jan-2022-cpu-12_2_1_4_0oracle-weblogic-jan-2022-cpu-14_1_1_0_0 | Feb 28, 2022 | Apr 13, 2021 | |
| Red Hat Jboss Eap | red-hat-jboss-eap-upgrade-latest | Sep 19, 2024 | Apr 12, 2021 | |
| Redhat_linux | — | no-fix-redhat-rpm-package | Jul 9, 2025 | Apr 13, 2021 |
| Splunk | splunk-upgrade-latest | Sep 30, 2025 | Apr 13, 2021 | |
| Suse | — | suse-upgrade-apache-commons-iosuse-upgrade-apache-commons-io-javadoc | Apr 24, 2021 | Apr 13, 2021 |
| Ubuntu | ubuntu-upgrade-libcommons-io-java | Sep 30, 2021 | Apr 13, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub