CVE-2021-29425Medium· 4.8▾ TwilightPoC availableIn Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent di…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 26.4 · likelihood 2 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Aug 25.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
10%
2 GitHub repos
In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to construct a path value.
commons_io = 2.2commons_io = 2.3commons_io = 2.4commons_io = 2.5commons_io = 2.6debian_linux = 9.0access_manager = 11.1.2.3.0access_manager = 12.2.1.3.0access_manager = 12.2.1.4.0agile_engineering_data_management = 6.2.1.0agile_product_lifecycle_management = 9.3.6application_performance_management = 13.4.1.0application_performance_management = 13.5.1.0application_testing_suite = 13.3.0.1banking_apis = 18.1banking_apis = 18.2banking_apis = 18.3banking_apis = 19.1banking_apis = 19.2banking_apis = 20.1banking_apis = 21.1banking_digital_experience = 17.2banking_digital_experience = 18.1banking_digital_experience = 18.3banking_digital_experience = 19.1banking_digital_experience = 19.2banking_digital_experience = 20.1banking_digital_experience = 21.1banking_enterprise_default_management = 2.6.2banking_enterprise_default_management = 2.7.0banking_enterprise_default_management = 2.7.1banking_enterprise_default_management = 2.10.0banking_enterprise_default_management = 2.12.0banking_enterprise_default_managment >= 2.3.0, <= 2.4.0banking_party_management = 2.7.0banking_platform >= 2.3.0, <= 2.4.1banking_platform = 2.6.2banking_platform = 2.7.0banking_platform = 2.7.1blockchain_platform < 21.1.2commerce_guided_search = 11.3.2communications_application_session_controller = 3.9.0communications_billing_and_revenue_management_elastic_charging_engine = 11.3communications_billing_and_revenue_management_elastic_charging_engine = 12.0communications_cloud_native_core_network_repository_function = 1.14.0communications_cloud_native_core_policy = 1.14.0communications_cloud_native_core_unified_data_repository = 1.4.0communications_contacts_server = 8.0.0.6.0communications_converged_application_server_-_service_controller = 6.2communications_convergence = 3.0.2.2.0communications_design_studio >= 7.4.0, <= 7.4.2communications_design_studio = 7.3.5communications_diameter_intelligence_hub >= 8.0.0, <= 8.1.0communications_diameter_intelligence_hub >= 8.2.0, <= 8.2.3communications_interactive_session_recorder = 6.3communications_interactive_session_recorder = 6.4communications_offline_mediation_controller = 12.0.0.3communications_order_and_service_management = 7.3communications_order_and_service_management = 7.4communications_policy_management = 12.5.0.0.0communications_pricing_design_center = 12.0.0.4.0communications_pricing_design_center = 12.0.0.5.0communications_service_broker = 6.2enterprise_communications_broker = 3.3enterprise_session_border_controller = 8.4enterprise_session_border_controller = 9.0financial_services_analytical_applications_infrastructure >= 8.0.7, <= 8.1.1financial_services_model_management_and_governance >= 8.0.8, <= 8.1.1flexcube_core_banking >= 11.6.0, <= 11.8.0flexcube_core_banking = 5.2.0flexcube_core_banking = 11.10.0fusion_middleware_mapviewer = 12.2.1.4.0health_sciences_data_management_workbench = 2.5.2.1health_sciences_data_management_workbench = 3.0.0.0health_sciences_information_manager >= 3.0.1, <= 3.0.4healthcare_data_repository = 8.1.0helidon = 1.4.7helidon = 2.2.0insurance_policy_administration = 11.0.2insurance_policy_administration = 11.1.0insurance_policy_administration = 11.2.8insurance_policy_administration = 11.3.0insurance_policy_administration = 11.3.1insurance_rules_palette = 11.0.2insurance_rules_palette = 11.1.0insurance_rules_palette = 11.2.8insurance_rules_palette = 11.3.0insurance_rules_palette = 11.3.1oss_support_tools < 2.12.42primavera_unifier >= 17.7, <= 17.12primavera_unifier = 18.8primavera_unifier = 19.12primavera_unifier = 20.12primavera_unifier = 21.12real_user_experience_insight = 13.4.1.0real_user_experience_insight = 13.5.1.0rest_data_services < 21.2rest_data_services = 21.3retail_assortment_planning = 16.0.3retail_integration_bus >= 16.0.1, <= 16.0.3Upgrade past the affected range:
blockchain_platform 21.1.2oss_support_tools 2.12.42rest_data_services 21.2Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2021-45105Medium· 5.9Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups
CVE-2021-3572Medium· 5.7A flaw was found in python-pip in the way it handled Unicode separators in git references
CVE-2026-84939Critical· 9.1Path traversal vulnerability in Apache FreeMarker template loading mechanism, if the attacker can specify an arbitrary malformed locale identifier to FreeMarker, and the localized lookup configuration setting is enabled (it's by default …
CVE-2026-78254High· 7.4The ftp and scp tasks of Apache Ant can download files from a remote server
CVE-2026-68569High· 8.1Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g
CVE-2026-49362High· 7.5An unauthenticated remote attacker can create arbitrary durable queues via the CORE protocol, leading to unauthorized broker state manipulation and potential denial of service. This issue affects Apache Artemis: from 2.50.0 through 2.56…