Relative Path Traversal vulnerability in Apache Commons VFS before 2.10.0.
The FileObject API in Commons VFS has a 'resolveFile' method that takes a 'scope' parameter. Specifying 'NameScope.DESCENDENT' promises that "an exception is thrown if the resolved file is not a descendent of the base file". However, when the path contains encoded ".." characters (for example, "%2E%2E/bar.txt"), it might return file objects that are not a descendent of the base file, without throwing an exception. This issue affects Apache Commons VFS: before 2.10.0.
Users are recommended to upgrade to version 2.10.0, which fixes the issue.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade apache-commons-vfs-javadocUpgrade apache-commons-vfsUpgrade apache-commons-vfs-examplesUpgrade apache-commons-vfs-ant | May 1, 2025 | Mar 23, 2025 |
| Debian | — | Upgrade commons-vfs | Apr 4, 2025 | Mar 23, 2025 |
| Oracle_linux | — | Upgrade apache-commons-vfs-examplesUpgrade apache-commons-vfs-antUpgrade apache-commons-vfs-javadocUpgrade apache-commons-vfs | Jul 25, 2025 | Mar 23, 2025 |
| Redhat_linux | — | Upgrade apache-commons-vfs-examplesUpgrade apache-commons-vfsUpgrade apache-commons-vfs-antUpgrade apache-commons-vfs-javadoc | Jun 17, 2026 | Mar 23, 2025 |
| Suse | — | Upgrade apache-commons-vfs2-javadocUpgrade apache-commons-vfs2-antUpgrade apache-commons-vfs2Upgrade apache-commons-vfs2-examples | Dec 5, 2025 | Mar 26, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub