← Back to CVE List

CVE-2021-29425

Published: 2021-04-13T07:15Z
Last Modified: 2024-11-21T06:01Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to construct a path value. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt