CVE-2021-29425

medium Apache
CVSS v3 Base Score
4.8
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
EPSS Score
10.2%
Exploitation probability in 30 days
Top 5% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Confidentiality
Low
Integrity
Low
Availability
None
Published: April 13, 2021 (1974 days ago)
Last Modified: August 25, 2026
Vendor: Apache
Source: NVD

Description

In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to construct a path value.

CWE

CWE-20

Affected Products

apache commons iodebian debian linuxoracle access manageroracle agile engineering data managementoracle agile product lifecycle managementoracle application performance managementoracle application testing suiteoracle banking apisoracle banking digital experienceoracle banking enterprise default management

References