{"id":"CVE-2021-29425","title":"In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like \"//../foo\", or \"\\\\..\\foo\", the result would be the same value, thus possibly providing access to files in the parent di…","summary":"In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like \"//../foo\", or \"\\\\..\\foo\", the result would be the same value, thus possibly providing access to files in the parent di…","severity":"medium","cvss":4.8,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","cwe":["CWE-20","CWE-22"],"vendor":"apache","product":"commons_io","affected":["commons_io = 2.2","commons_io = 2.3","commons_io = 2.4","commons_io = 2.5","commons_io = 2.6","debian_linux = 9.0","access_manager = 11.1.2.3.0","access_manager = 12.2.1.3.0","access_manager = 12.2.1.4.0","agile_engineering_data_management = 6.2.1.0","agile_product_lifecycle_management = 9.3.6","application_performance_management = 13.4.1.0","application_performance_management = 13.5.1.0","application_testing_suite = 13.3.0.1","banking_apis = 18.1","banking_apis = 18.2","banking_apis = 18.3","banking_apis = 19.1","banking_apis = 19.2","banking_apis = 20.1","banking_apis = 21.1","banking_digital_experience = 17.2","banking_digital_experience = 18.1","banking_digital_experience = 18.3","banking_digital_experience = 19.1","banking_digital_experience = 19.2","banking_digital_experience = 20.1","banking_digital_experience = 21.1","banking_enterprise_default_management = 2.6.2","banking_enterprise_default_management = 2.7.0","banking_enterprise_default_management = 2.7.1","banking_enterprise_default_management = 2.10.0","banking_enterprise_default_management = 2.12.0","banking_enterprise_default_managment >= 2.3.0, <= 2.4.0","banking_party_management = 2.7.0","banking_platform >= 2.3.0, <= 2.4.1","banking_platform = 2.6.2","banking_platform = 2.7.0","banking_platform = 2.7.1","blockchain_platform < 21.1.2","commerce_guided_search = 11.3.2","communications_application_session_controller = 3.9.0","communications_billing_and_revenue_management_elastic_charging_engine = 11.3","communications_billing_and_revenue_management_elastic_charging_engine = 12.0","communications_cloud_native_core_network_repository_function = 1.14.0","communications_cloud_native_core_policy = 1.14.0","communications_cloud_native_core_unified_data_repository = 1.4.0","communications_contacts_server = 8.0.0.6.0","communications_converged_application_server_-_service_controller = 6.2","communications_convergence = 3.0.2.2.0","communications_design_studio >= 7.4.0, <= 7.4.2","communications_design_studio = 7.3.5","communications_diameter_intelligence_hub >= 8.0.0, <= 8.1.0","communications_diameter_intelligence_hub >= 8.2.0, <= 8.2.3","communications_interactive_session_recorder = 6.3","communications_interactive_session_recorder = 6.4","communications_offline_mediation_controller = 12.0.0.3","communications_order_and_service_management = 7.3","communications_order_and_service_management = 7.4","communications_policy_management = 12.5.0.0.0","communications_pricing_design_center = 12.0.0.4.0","communications_pricing_design_center = 12.0.0.5.0","communications_service_broker = 6.2","enterprise_communications_broker = 3.3","enterprise_session_border_controller = 8.4","enterprise_session_border_controller = 9.0","financial_services_analytical_applications_infrastructure >= 8.0.7, <= 8.1.1","financial_services_model_management_and_governance >= 8.0.8, <= 8.1.1","flexcube_core_banking >= 11.6.0, <= 11.8.0","flexcube_core_banking = 5.2.0","flexcube_core_banking = 11.10.0","fusion_middleware_mapviewer = 12.2.1.4.0","health_sciences_data_management_workbench = 2.5.2.1","health_sciences_data_management_workbench = 3.0.0.0","health_sciences_information_manager >= 3.0.1, <= 3.0.4","healthcare_data_repository = 8.1.0","helidon = 1.4.7","helidon = 2.2.0","insurance_policy_administration = 11.0.2","insurance_policy_administration = 11.1.0","insurance_policy_administration = 11.2.8","insurance_policy_administration = 11.3.0","insurance_policy_administration = 11.3.1","insurance_rules_palette = 11.0.2","insurance_rules_palette = 11.1.0","insurance_rules_palette = 11.2.8","insurance_rules_palette = 11.3.0","insurance_rules_palette = 11.3.1","oss_support_tools < 2.12.42","primavera_unifier >= 17.7, <= 17.12","primavera_unifier = 18.8","primavera_unifier = 19.12","primavera_unifier = 20.12","primavera_unifier = 21.12","real_user_experience_insight = 13.4.1.0","real_user_experience_insight = 13.5.1.0","rest_data_services < 21.2","rest_data_services = 21.3","retail_assortment_planning = 16.0.3","retail_integration_bus >= 16.0.1, <= 16.0.3"],"patched":["blockchain_platform 21.1.2","oss_support_tools 2.12.42","rest_data_services 21.2"],"published":"2021-04-13","updated":"2026-08-25","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2021-29425","references":[{"url":"https://issues.apache.org/jira/browse/IO-556","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r01b4a1fcdf3311c936ce33d75a9398b6c255f00c1a2f312ac21effe1%40%3Cnotifications.zookeeper.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r0bfa8f7921abdfae788b1f076a12f73a92c93cc0a6e1083bce0027c5%40%3Cnotifications.zookeeper.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r0d73e2071d1f1afe1a15da14c5b6feb2cf17e3871168d5a3c8451436%40%3Ccommits.pulsar.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r1c2f4683c35696cf6f863e3c107e37ec41305b1930dd40c17260de71%40%3Ccommits.pulsar.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r20416f39ca7f7344e7d76fe4d7063bb1d91ad106926626e7e83fb346%40%3Cnotifications.zookeeper.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r2345b49dbffa8a5c3c589c082fe39228a2c1d14f11b96c523da701db%40%3Cnotifications.zookeeper.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r2721aba31a8562639c4b937150897e24f78f747cdbda8641c0f659fe%40%3Cusers.kafka.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r27b1eedda37468256c4bb768fde1e8b79b37ec975cbbfd0d65a7ac34%40%3Cdev.myfaces.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r2bc986a070457daca457a54fe71ee09d2584c24dc262336ca32b6a19%40%3Cdev.creadur.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r2df50af2641d38f432ef025cd2ba5858215cc0cf3fc10396a674ad2e%40%3Cpluto-scm.portals.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r345330b7858304938b7b8029d02537a116d75265a598c98fa333504a%40%3Cdev.creadur.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r4050f9f6b42ebfa47a98cbdee4aabed4bb5fb8093db7dbb88faceba2%40%3Ccommits.zookeeper.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r462db908acc1e37c455e11b1a25992b81efd18e641e7e0ceb1b6e046%40%3Cnotifications.zookeeper.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r477c285126ada5c3b47946bb702cb222ac4e7fd3100c8549bdd6d3b2%40%3Cissues.zookeeper.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r47ab6f68cbba8e730f42c4ea752f3a44eb95fb09064070f2476bb401%40%3Cdev.creadur.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r5149f78be265be69d34eacb4e4b0fc7c9c697bcdfa91a1c1658d717b%40%3Cissues.zookeeper.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r523a6ffad58f71c4f3761e3cee72df878e48cdc89ebdce933be1475c%40%3Cdev.creadur.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r808be7d93b17a7055c1981a8453ae5f0d0fce5855407793c5d0ffffa%40%3Cuser.commons.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r8569a41d565ca880a4dee0e645dad1cd17ab4a92e68055ad9ebb7375%40%3Cdev.creadur.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r86528f4b7d222aed7891e7ac03d69a0db2a2dfa17b86ac3470d7f374%40%3Cnotifications.zookeeper.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r873d5ddafc0a68fd999725e559776dc4971d1ab39c0f5cc81bd9bc04%40%3Ccommits.pulsar.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r8bfc7235e6b39d90e6f446325a5a44c3e9e50da18860fdabcee23e29%40%3Cissues.zookeeper.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r8efcbabde973ea72f5e0933adc48ef1425db5cde850bf641b3993f31%40%3Cdev.commons.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r92ea904f4bae190b03bd42a4355ce3c2fbe8f36ab673e03f6ca3f9fa%40%3Cnotifications.zookeeper.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/ra8ef65aedc086d2d3d21492b4c08ae0eb8a3a42cc52e29ba1bc009d8%40%3Cdev.creadur.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/raa053846cae9d497606027816ae87b4e002b2e0eb66cb0dee710e1f5%40%3Cdev.creadur.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/rad4ae544747df32ccd58fff5a86cd556640396aeb161aa71dd3d192a%40%3Cuser.commons.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/rbebd3e19651baa7a4a5503a9901c95989df9d40602c8e35cb05d3eb5%40%3Cdev.creadur.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/rc10fa20ef4d13cbf6ebe0b06b5edb95466a1424a9b7673074ed03260%40%3Cnotifications.zookeeper.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/rc2dd3204260e9227a67253ef68b6f1599446005bfa0e1ddce4573a80%40%3Cpluto-dev.portals.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/rc359823b5500e9a9a2572678ddb8e01d3505a7ffcadfa8d13b8780ab%40%3Cuser.commons.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/rc5f3df5316c5237b78a3dff5ab95b311ad08e61d418cd992ca7e34ae%40%3Cnotifications.zookeeper.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/rc65f9bc679feffe4589ea0981ee98bc0af9139470f077a91580eeee0%40%3Cpluto-dev.portals.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/rca71a10ca533eb9bfac2d590533f02e6fb9064d3b6aa3ec90fdc4f51%40%3Cnotifications.zookeeper.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/rd09d4ab3e32e4b3a480e2ff6ff118712981ca82e817f28f2a85652a6%40%3Cnotifications.zookeeper.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/re41e9967bee064e7369411c28f0f5b2ad28b8334907c9c6208017279%40%3Cnotifications.zookeeper.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/red3aea910403d8620c73e1c7b9c9b145798d0469eb3298a7be7891af%40%3Cnotifications.zookeeper.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/rfa2f08b7c0caf80ca9f4a18bd875918fdd4e894e2ea47942a4589b9c%40%3Cdev.creadur.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/rfcd2c649c205f12b72dde044f905903460669a220a2eb7e12652d19d%40%3Cdev.zookeeper.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/rfd01af05babc95b8949e6d8ea78d9834699e1b06981040dde419a330%40%3Cdev.commons.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.debian.org/debian-lts-announce/2021/08/msg00016.html","label":"security@apache.org"},{"url":"https://security.netapp.com/advisory/ntap-20220210-0004/","label":"security@apache.org"},{"url":"https://www.oracle.com/security-alerts/cpuapr2022.html","label":"security@apache.org"},{"url":"https://www.oracle.com/security-alerts/cpujan2022.html","label":"security@apache.org"},{"url":"https://www.oracle.com/security-alerts/cpujul2022.html","label":"security@apache.org"},{"url":"https://www.oracle.com/security-alerts/cpuoct2021.html","label":"security@apache.org"},{"url":"https://issues.apache.org/jira/browse/IO-556","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r01b4a1fcdf3311c936ce33d75a9398b6c255f00c1a2f312ac21effe1%40%3Cnotifications.zookeeper.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r0bfa8f7921abdfae788b1f076a12f73a92c93cc0a6e1083bce0027c5%40%3Cnotifications.zookeeper.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r0d73e2071d1f1afe1a15da14c5b6feb2cf17e3871168d5a3c8451436%40%3Ccommits.pulsar.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r1c2f4683c35696cf6f863e3c107e37ec41305b1930dd40c17260de71%40%3Ccommits.pulsar.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r20416f39ca7f7344e7d76fe4d7063bb1d91ad106926626e7e83fb346%40%3Cnotifications.zookeeper.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r2345b49dbffa8a5c3c589c082fe39228a2c1d14f11b96c523da701db%40%3Cnotifications.zookeeper.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r2721aba31a8562639c4b937150897e24f78f747cdbda8641c0f659fe%40%3Cusers.kafka.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r27b1eedda37468256c4bb768fde1e8b79b37ec975cbbfd0d65a7ac34%40%3Cdev.myfaces.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r2bc986a070457daca457a54fe71ee09d2584c24dc262336ca32b6a19%40%3Cdev.creadur.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r2df50af2641d38f432ef025cd2ba5858215cc0cf3fc10396a674ad2e%40%3Cpluto-scm.portals.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r345330b7858304938b7b8029d02537a116d75265a598c98fa333504a%40%3Cdev.creadur.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r4050f9f6b42ebfa47a98cbdee4aabed4bb5fb8093db7dbb88faceba2%40%3Ccommits.zookeeper.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r462db908acc1e37c455e11b1a25992b81efd18e641e7e0ceb1b6e046%40%3Cnotifications.zookeeper.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r477c285126ada5c3b47946bb702cb222ac4e7fd3100c8549bdd6d3b2%40%3Cissues.zookeeper.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r47ab6f68cbba8e730f42c4ea752f3a44eb95fb09064070f2476bb401%40%3Cdev.creadur.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r5149f78be265be69d34eacb4e4b0fc7c9c697bcdfa91a1c1658d717b%40%3Cissues.zookeeper.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r523a6ffad58f71c4f3761e3cee72df878e48cdc89ebdce933be1475c%40%3Cdev.creadur.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r808be7d93b17a7055c1981a8453ae5f0d0fce5855407793c5d0ffffa%40%3Cuser.commons.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r8569a41d565ca880a4dee0e645dad1cd17ab4a92e68055ad9ebb7375%40%3Cdev.creadur.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r86528f4b7d222aed7891e7ac03d69a0db2a2dfa17b86ac3470d7f374%40%3Cnotifications.zookeeper.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r873d5ddafc0a68fd999725e559776dc4971d1ab39c0f5cc81bd9bc04%40%3Ccommits.pulsar.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r8bfc7235e6b39d90e6f446325a5a44c3e9e50da18860fdabcee23e29%40%3Cissues.zookeeper.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r8efcbabde973ea72f5e0933adc48ef1425db5cde850bf641b3993f31%40%3Cdev.commons.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r92ea904f4bae190b03bd42a4355ce3c2fbe8f36ab673e03f6ca3f9fa%40%3Cnotifications.zookeeper.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/ra8ef65aedc086d2d3d21492b4c08ae0eb8a3a42cc52e29ba1bc009d8%40%3Cdev.creadur.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/raa053846cae9d497606027816ae87b4e002b2e0eb66cb0dee710e1f5%40%3Cdev.creadur.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rad4ae544747df32ccd58fff5a86cd556640396aeb161aa71dd3d192a%40%3Cuser.commons.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rbebd3e19651baa7a4a5503a9901c95989df9d40602c8e35cb05d3eb5%40%3Cdev.creadur.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rc10fa20ef4d13cbf6ebe0b06b5edb95466a1424a9b7673074ed03260%40%3Cnotifications.zookeeper.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rc2dd3204260e9227a67253ef68b6f1599446005bfa0e1ddce4573a80%40%3Cpluto-dev.portals.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rc359823b5500e9a9a2572678ddb8e01d3505a7ffcadfa8d13b8780ab%40%3Cuser.commons.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rc5f3df5316c5237b78a3dff5ab95b311ad08e61d418cd992ca7e34ae%40%3Cnotifications.zookeeper.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rc65f9bc679feffe4589ea0981ee98bc0af9139470f077a91580eeee0%40%3Cpluto-dev.portals.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rca71a10ca533eb9bfac2d590533f02e6fb9064d3b6aa3ec90fdc4f51%40%3Cnotifications.zookeeper.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rd09d4ab3e32e4b3a480e2ff6ff118712981ca82e817f28f2a85652a6%40%3Cnotifications.zookeeper.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/re41e9967bee064e7369411c28f0f5b2ad28b8334907c9c6208017279%40%3Cnotifications.zookeeper.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/red3aea910403d8620c73e1c7b9c9b145798d0469eb3298a7be7891af%40%3Cnotifications.zookeeper.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rfa2f08b7c0caf80ca9f4a18bd875918fdd4e894e2ea47942a4589b9c%40%3Cdev.creadur.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rfcd2c649c205f12b72dde044f905903460669a220a2eb7e12652d19d%40%3Cdev.zookeeper.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rfd01af05babc95b8949e6d8ea78d9834699e1b06981040dde419a330%40%3Cdev.commons.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2021/08/msg00016.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20220210-0004/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuapr2022.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpujan2022.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpujul2022.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuoct2021.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-29425.json"},{"url":"https://access.redhat.com/security/cve/CVE-2021-29425"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1948752"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-29425"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-29425"},{"url":"https://access.redhat.com/errata/RHSA-2021:3466"},{"url":"https://access.redhat.com/errata/RHSA-2021:3467"},{"url":"https://access.redhat.com/errata/RHSA-2021:3656"},{"url":"https://access.redhat.com/errata/RHSA-2021:3468"},{"url":"https://access.redhat.com/errata/RHSA-2021:3658"},{"url":"https://access.redhat.com/errata/RHSA-2021:3471"},{"url":"https://access.redhat.com/errata/RHSA-2022:1110"},{"url":"https://access.redhat.com/errata/RHSA-2022:1108"},{"url":"https://access.redhat.com/errata/RHSA-2021:3700"},{"url":"https://access.redhat.com/errata/RHSA-2021:3225"},{"url":"https://access.redhat.com/errata/RHSA-2021:3516"},{"url":"https://access.redhat.com/errata/RHSA-2021:5134"},{"url":"https://access.redhat.com/errata/RHSA-2021:3660"},{"url":"https://access.redhat.com/errata/RHSA-2021:3534"},{"url":"https://access.redhat.com/errata/RHSA-2021:2465"}],"tags":["nvd","exploit-available","csaf","vex","red-hat"],"epss":0.10233,"epssPercentile":0.95527,"ingestedAt":"2026-08-25T17:29:31.210Z","exploits":{"github":2,"githubRepos":["https://github.com/arsalanraja987/java-cve-2021-29425-tika-xxe","https://github.com/shoucheng3/asf__commons-io_CVE-2021-29425_2-6"],"checkedAt":"2026-09-21T15:24:13.411Z"},"exploitAvailable":true,"slug":"CVE-2021-29425","body":"## Overview\n\nIn Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like \"//../foo\", or \"\\\\..\\foo\", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus \"limited\" path traversal), if the calling code would use the result to construct a path value.\n\n## Affected\n\n- `commons_io = 2.2`\n- `commons_io = 2.3`\n- `commons_io = 2.4`\n- `commons_io = 2.5`\n- `commons_io = 2.6`\n- `debian_linux = 9.0`\n- `access_manager = 11.1.2.3.0`\n- `access_manager = 12.2.1.3.0`\n- `access_manager = 12.2.1.4.0`\n- `agile_engineering_data_management = 6.2.1.0`\n- `agile_product_lifecycle_management = 9.3.6`\n- `application_performance_management = 13.4.1.0`\n- `application_performance_management = 13.5.1.0`\n- `application_testing_suite = 13.3.0.1`\n- `banking_apis = 18.1`\n- `banking_apis = 18.2`\n- `banking_apis = 18.3`\n- `banking_apis = 19.1`\n- `banking_apis = 19.2`\n- `banking_apis = 20.1`\n- `banking_apis = 21.1`\n- `banking_digital_experience = 17.2`\n- `banking_digital_experience = 18.1`\n- `banking_digital_experience = 18.3`\n- `banking_digital_experience = 19.1`\n- `banking_digital_experience = 19.2`\n- `banking_digital_experience = 20.1`\n- `banking_digital_experience = 21.1`\n- `banking_enterprise_default_management = 2.6.2`\n- `banking_enterprise_default_management = 2.7.0`\n- `banking_enterprise_default_management = 2.7.1`\n- `banking_enterprise_default_management = 2.10.0`\n- `banking_enterprise_default_management = 2.12.0`\n- `banking_enterprise_default_managment >= 2.3.0, <= 2.4.0`\n- `banking_party_management = 2.7.0`\n- `banking_platform >= 2.3.0, <= 2.4.1`\n- `banking_platform = 2.6.2`\n- `banking_platform = 2.7.0`\n- `banking_platform = 2.7.1`\n- `blockchain_platform < 21.1.2`\n- `commerce_guided_search = 11.3.2`\n- `communications_application_session_controller = 3.9.0`\n- `communications_billing_and_revenue_management_elastic_charging_engine = 11.3`\n- `communications_billing_and_revenue_management_elastic_charging_engine = 12.0`\n- `communications_cloud_native_core_network_repository_function = 1.14.0`\n- `communications_cloud_native_core_policy = 1.14.0`\n- `communications_cloud_native_core_unified_data_repository = 1.4.0`\n- `communications_contacts_server = 8.0.0.6.0`\n- `communications_converged_application_server_-_service_controller = 6.2`\n- `communications_convergence = 3.0.2.2.0`\n- `communications_design_studio >= 7.4.0, <= 7.4.2`\n- `communications_design_studio = 7.3.5`\n- `communications_diameter_intelligence_hub >= 8.0.0, <= 8.1.0`\n- `communications_diameter_intelligence_hub >= 8.2.0, <= 8.2.3`\n- `communications_interactive_session_recorder = 6.3`\n- `communications_interactive_session_recorder = 6.4`\n- `communications_offline_mediation_controller = 12.0.0.3`\n- `communications_order_and_service_management = 7.3`\n- `communications_order_and_service_management = 7.4`\n- `communications_policy_management = 12.5.0.0.0`\n- `communications_pricing_design_center = 12.0.0.4.0`\n- `communications_pricing_design_center = 12.0.0.5.0`\n- `communications_service_broker = 6.2`\n- `enterprise_communications_broker = 3.3`\n- `enterprise_session_border_controller = 8.4`\n- `enterprise_session_border_controller = 9.0`\n- `financial_services_analytical_applications_infrastructure >= 8.0.7, <= 8.1.1`\n- `financial_services_model_management_and_governance >= 8.0.8, <= 8.1.1`\n- `flexcube_core_banking >= 11.6.0, <= 11.8.0`\n- `flexcube_core_banking = 5.2.0`\n- `flexcube_core_banking = 11.10.0`\n- `fusion_middleware_mapviewer = 12.2.1.4.0`\n- `health_sciences_data_management_workbench = 2.5.2.1`\n- `health_sciences_data_management_workbench = 3.0.0.0`\n- `health_sciences_information_manager >= 3.0.1, <= 3.0.4`\n- `healthcare_data_repository = 8.1.0`\n- `helidon = 1.4.7`\n- `helidon = 2.2.0`\n- `insurance_policy_administration = 11.0.2`\n- `insurance_policy_administration = 11.1.0`\n- `insurance_policy_administration = 11.2.8`\n- `insurance_policy_administration = 11.3.0`\n- `insurance_policy_administration = 11.3.1`\n- `insurance_rules_palette = 11.0.2`\n- `insurance_rules_palette = 11.1.0`\n- `insurance_rules_palette = 11.2.8`\n- `insurance_rules_palette = 11.3.0`\n- `insurance_rules_palette = 11.3.1`\n- `oss_support_tools < 2.12.42`\n- `primavera_unifier >= 17.7, <= 17.12`\n- `primavera_unifier = 18.8`\n- `primavera_unifier = 19.12`\n- `primavera_unifier = 20.12`\n- `primavera_unifier = 21.12`\n- `real_user_experience_insight = 13.4.1.0`\n- `real_user_experience_insight = 13.5.1.0`\n- `rest_data_services < 21.2`\n- `rest_data_services = 21.3`\n- `retail_assortment_planning = 16.0.3`\n- `retail_integration_bus >= 16.0.1, <= 16.0.3`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `blockchain_platform 21.1.2`\n- `oss_support_tools 2.12.42`\n- `rest_data_services 21.2`\n\n## Vendor advisories\n\n- **RHSA-2021:3466** · Red Hat · fixed in: Red Hat JBoss EAP 7.3 for RHEL 6 Server · released 2021-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2021:3466)\n- **RHSA-2021:3467** · Red Hat · fixed in: Red Hat JBoss EAP 7.3 for RHEL 7 Server · released 2021-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2021:3467)\n- **RHSA-2021:3656** · Red Hat · fixed in: Red Hat JBoss EAP 7.4 for RHEL 7 Server · released 2021-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2021:3656)\n- **RHSA-2021:3468** · Red Hat · fixed in: Red Hat JBoss EAP 7.3 for BaseOS-8 · released 2021-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2021:3468)\n- **RHSA-2021:3658** · Red Hat · fixed in: Red Hat JBoss EAP 7.4 for RHEL 8 · released 2021-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2021:3658)\n- **RHSA-2021:3471** · Red Hat · fixed in: EAP 7.3.9 release · released 2021-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2021:3471)\n- **RHSA-2022:1110** · Red Hat · fixed in: RHDM 7.12.1 · released 2022-03-29 · [advisory](https://access.redhat.com/errata/RHSA-2022:1110)\n- **RHSA-2022:1108** · Red Hat · fixed in: RHPAM 7.12.1 · released 2022-03-29 · [advisory](https://access.redhat.com/errata/RHSA-2022:1108)\n- **RHSA-2021:3700** · Red Hat · fixed in: Red Hat AMQ 7.9.0 · released 2021-09-30 · [advisory](https://access.redhat.com/errata/RHSA-2021:3700)\n- **RHSA-2021:3225** · Red Hat · fixed in: Red Hat AMQ Streams 1.8.0 · released 2021-08-19 · [advisory](https://access.redhat.com/errata/RHSA-2021:3225)\n- **RHSA-2021:3516** · Red Hat · fixed in: Red Hat EAP-XP 2.0.0 via EAP 7.3.x base · released 2021-09-13 · [advisory](https://access.redhat.com/errata/RHSA-2021:3516)\n- **Red Hat VEX** · Moderate · affected: A-MQ Clients 2, Red Hat BPM Suite 6, Red Hat Data Grid 8, Red Hat Enterprise Linux 7, Red Hat JBoss A-MQ 6, Red Hat JBoss BRMS 6, … · no fix planned: Red Hat BPM Suite 6, Red Hat Enterprise Linux 7, Red Hat JBoss A-MQ 6, Red Hat JBoss BRMS 6, … · updated 2026-09-07 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-29425.json)","depth":"twilight","depthScore":40,"depthScoreParts":{"impact":26.4,"likelihood":2,"exploitation":12,"ransomware":0},"changes":[{"seq":4518,"id":"CVE-2021-29425","ts":1788887186505,"field":"exploit_available","old":"false","new":"true"},{"seq":3401,"id":"CVE-2021-29425","ts":1788886304203,"field":"exploit_available","old":"true","new":"false"},{"seq":2256,"id":"CVE-2021-29425","ts":1788882973798,"field":"exploit_available","old":"false","new":"true"},{"seq":1285,"id":"CVE-2021-29425","ts":1788882385532,"field":"exploit_available","old":"true","new":"false"},{"seq":399,"id":"CVE-2021-29425","ts":1788881820904,"field":"exploit_available","old":"false","new":"true"}]}