CVE-2021-29425

In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to construct a path value.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.8 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
apacheCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 57%
VendorProductVersion
apachecommons_io
2.2
apachecommons_io
2.3
apachecommons_io
2.4
apachecommons_io
2.5
apachecommons_io
2.6
debiandebian_linux
9.0
oracleaccess_manager
11.1.2.3.0
oracleaccess_manager
12.2.1.3.0
oracleaccess_manager
12.2.1.4.0
oracleagile_engineering_data_management
6.2.1.0
oracleagile_plm
9.3.6
oracleapplication_performance_management
13.4.1.0
oracleapplication_performance_management
13.5.1.0
oracleapplication_testing_suite
13.3.0.1
oraclebanking_apis
18.1
oraclebanking_apis
18.2
oraclebanking_apis
18.3
oraclebanking_apis
19.1
oraclebanking_apis
19.2
oraclebanking_apis
20.1
oraclebanking_apis
21.1
oraclebanking_digital_experience
17.2
oraclebanking_digital_experience
18.1
oraclebanking_digital_experience
18.3
oraclebanking_digital_experience
19.1
oraclebanking_digital_experience
19.2
oraclebanking_digital_experience
20.1
oraclebanking_digital_experience
21.1
oraclebanking_enterprise_default_management
2.6.2
oraclebanking_enterprise_default_management
2.7.0
oraclebanking_enterprise_default_management
2.7.1
oraclebanking_enterprise_default_management
2.10.0
oraclebanking_enterprise_default_management
2.12.0
oraclebanking_enterprise_default_managment
2.3.0 ≤
𝑥
≤ 2.4.0
oraclebanking_party_management
2.7.0
oraclebanking_platform
2.3.0 ≤
𝑥
≤ 2.4.1
oraclebanking_platform
2.6.2
oraclebanking_platform
2.7.0
oraclebanking_platform
2.7.1
oracleblockchain_platform
𝑥
< 21.1.2
oraclecommerce_guided_search
11.3.2
oraclecommunications_application_session_controller
3.9.0
oraclecommunications_billing_and_revenue_management_elastic_charging_engine
11.3
oraclecommunications_billing_and_revenue_management_elastic_charging_engine
12.0
oraclecommunications_cloud_native_core_network_repository_function
1.14.0
oraclecommunications_cloud_native_core_policy
1.14.0
oraclecommunications_cloud_native_core_unified_data_repository
1.4.0
oraclecommunications_contacts_server
8.0.0.6.0
oraclecommunications_converged_application_server_-_service_controller
6.2
oraclecommunications_convergence
3.0.2.2.0
oraclecommunications_design_studio
7.4.0 ≤
𝑥
≤ 7.4.2
oraclecommunications_design_studio
7.3.5
oraclecommunications_diameter_intelligence_hub
8.0.0 ≤
𝑥
≤ 8.1.0
oraclecommunications_diameter_intelligence_hub
8.2.0 ≤
𝑥
≤ 8.2.3
oraclecommunications_interactive_session_recorder
6.3
oraclecommunications_interactive_session_recorder
6.4
oraclecommunications_offline_mediation_controller
12.0.0.3
oraclecommunications_order_and_service_management
7.3
oraclecommunications_order_and_service_management
7.4
oraclecommunications_policy_management
12.5.0.0.0
oraclecommunications_pricing_design_center
12.0.0.4.0
oraclecommunications_pricing_design_center
12.0.0.5.0
oraclecommunications_service_broker
6.2
oracleenterprise_communications_broker
3.3
oracleenterprise_session_border_controller
8.4
oracleenterprise_session_border_controller
9.0
oraclefinancial_services_analytical_applications_infrastructure
8.0.7 ≤
𝑥
≤ 8.1.1
oraclefinancial_services_model_management_and_governance
8.0.8 ≤
𝑥
≤ 8.1.1
oracleflexcube_core_banking
11.6.0 ≤
𝑥
≤ 11.8.0
oracleflexcube_core_banking
5.2.0
oracleflexcube_core_banking
11.10.0
oraclefusion_middleware_mapviewer
12.2.1.4.0
oraclehealth_sciences_data_management_workbench
2.5.2.1
oraclehealth_sciences_data_management_workbench
3.0.0.0
oraclehealth_sciences_information_manager
3.0.1 ≤
𝑥
≤ 3.0.4
oraclehealthcare_data_repository
8.1.0
oraclehelidon
1.4.7
oraclehelidon
2.2.0
oracleinsurance_policy_administration
11.0.2
oracleinsurance_policy_administration
11.1.0
oracleinsurance_policy_administration
11.2.8
oracleinsurance_policy_administration
11.3.0
oracleinsurance_policy_administration
11.3.1
oracleinsurance_rules_palette
11.0.2
oracleinsurance_rules_palette
11.1.0
oracleinsurance_rules_palette
11.2.8
oracleinsurance_rules_palette
11.3.0
oracleinsurance_rules_palette
11.3.1
oracleoss_support_tools
𝑥
< 2.12.42
oracleprimavera_unifier
17.7 ≤
𝑥
≤ 17.12
oracleprimavera_unifier
18.8
oracleprimavera_unifier
19.12
oracleprimavera_unifier
20.12
oracleprimavera_unifier
21.12
oraclereal_user_experience_insight
13.4.1.0
oraclereal_user_experience_insight
13.5.1.0
oraclerest_data_services
𝑥
< 21.2
oraclerest_data_services
21.3
oracleretail_assortment_planning
16.0.3
oracleretail_integration_bus
16.0.1 ≤
𝑥
≤ 16.0.3
oracleretail_integration_bus
13.0
oracleretail_integration_bus
14.1.3.0
oracleretail_integration_bus
14.1.3.2
oracleretail_integration_bus
15.0.3.1
oracleretail_integration_bus
19.0.0
oracleretail_integration_bus
19.0.1
oracleretail_merchandising_system
16.0.3
oracleretail_merchandising_system
19.0.1
oracleretail_order_broker
16.0
oracleretail_order_broker
18.0
oracleretail_order_broker
19.1
oracleretail_pricing
19.0.1
oracleretail_service_backbone
16.0.1 ≤
𝑥
≤ 16.0.3
oracleretail_service_backbone
14.1.3.0
oracleretail_service_backbone
14.1.3.2
oracleretail_service_backbone
15.0.3.1
oracleretail_service_backbone
19.0.0
oracleretail_service_backbone
19.0.1
oracleretail_size_profile_optimization
16.0.3
oracleretail_xstore_point_of_service
17.0.4
oracleretail_xstore_point_of_service
18.0.3
oracleretail_xstore_point_of_service
19.0.2
oracleretail_xstore_point_of_service
20.0.1
oraclesolaris_cluster
4.0
oracleutilities_testing_accelerator
6.0.0.1.1
oracleutilities_testing_accelerator
6.0.0.2.2
oracleutilities_testing_accelerator
6.0.0.3.1
oraclewebcenter_portal
12.2.1.3.0
oraclewebcenter_portal
12.2.1.4.0
oracleweblogic_server
12.1.3.0.0
oracleweblogic_server
12.2.1.3.0
oracleweblogic_server
12.2.1.4.0
oracleweblogic_server
14.1.1.0.0
netappactive_iq_unified_manager
-
netappactive_iq_unified_manager
-
netappactive_iq_unified_manager
-
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
commons-io
bullseye
2.8.0-1
fixed
bookworm
2.11.0-2
fixed
sid
2.17.0-1
fixed
trixie
2.17.0-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
commons-io
noble
not-affected
mantic
not-affected
lunar
not-affected
kinetic
not-affected
jammy
not-affected
impish
not-affected
hirsute
not-affected
groovy
ignored
focal
Fixed 2.6-2ubuntu0.20.04.1
released
bionic
Fixed 2.6-2ubuntu0.18.04.1
released
xenial
needed
trusty
Fixed 2.4-2ubuntu0.1~esm1
released
References