In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to construct a path value.
CVSS Details
- CVSS 3.1 Base Score: 4.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade apache-commons-ioUpgrade apache-commons-io-javadoc | Jun 6, 2023 | Apr 13, 2021 |
| Debian | — | Upgrade commons-io | Aug 16, 2021 | Apr 13, 2021 |
| Oracle Weblogic | — | Apply the Patch Set Update (PSU) 33494824 for version 12.1.3.0.0.Apply the Patch Set Update (PSU) 33727616 for version 12.2.1.4.0.Apply the Patch Set Update (PSU) 33727619 for version 14.1.1.0.0.Apply the Patch Set Update (PSU) 33699205 for version 12.2.1.3.0. | Feb 28, 2022 | Apr 13, 2021 |
| Red Hat Jboss Eap | — | Upgrade Red Hat JBoss EAP to the latest version | Sep 19, 2024 | Apr 12, 2021 |
| Red_hat Jboss_eap | — | — | Apr 10, 2023 | Apr 13, 2021 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Apr 13, 2021 |
| Splunk | — | Upgrade Splunk Enterprise to version 9.2.2Upgrade Splunk Enterprise to version 9.1.5Upgrade Splunk Enterprise to version 9.0.10 | Sep 30, 2025 | Apr 13, 2021 |
| Suse | — | Upgrade apache-commons-io-javadocUpgrade apache-commons-io | Apr 24, 2021 | Apr 13, 2021 |
| Ubuntu | — | Upgrade libcommons-io-java | Sep 30, 2021 | Apr 13, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub