---
id: CVE-2021-29425
title: >-
  In Apache Commons IO before 2.7, When invoking the method
  FileNameUtils.normalize with an improper input string, like "//../foo", or
  "\\..\foo", the result would be the same value, thus possibly providing access
  to files in the parent di…
summary: >-
  In Apache Commons IO before 2.7, When invoking the method
  FileNameUtils.normalize with an improper input string, like "//../foo", or
  "\\..\foo", the result would be the same value, thus possibly providing access
  to files in the parent di…
severity: medium
cvss: 4.8
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-20
  - CWE-22
vendor: apache
product: commons_io
affected:
  - commons_io = 2.2
  - commons_io = 2.3
  - commons_io = 2.4
  - commons_io = 2.5
  - commons_io = 2.6
  - debian_linux = 9.0
  - access_manager = 11.1.2.3.0
  - access_manager = 12.2.1.3.0
  - access_manager = 12.2.1.4.0
  - agile_engineering_data_management = 6.2.1.0
  - agile_product_lifecycle_management = 9.3.6
  - application_performance_management = 13.4.1.0
  - application_performance_management = 13.5.1.0
  - application_testing_suite = 13.3.0.1
  - banking_apis = 18.1
  - banking_apis = 18.2
  - banking_apis = 18.3
  - banking_apis = 19.1
  - banking_apis = 19.2
  - banking_apis = 20.1
  - banking_apis = 21.1
  - banking_digital_experience = 17.2
  - banking_digital_experience = 18.1
  - banking_digital_experience = 18.3
  - banking_digital_experience = 19.1
  - banking_digital_experience = 19.2
  - banking_digital_experience = 20.1
  - banking_digital_experience = 21.1
  - banking_enterprise_default_management = 2.6.2
  - banking_enterprise_default_management = 2.7.0
  - banking_enterprise_default_management = 2.7.1
  - banking_enterprise_default_management = 2.10.0
  - banking_enterprise_default_management = 2.12.0
  - 'banking_enterprise_default_managment >= 2.3.0, <= 2.4.0'
  - banking_party_management = 2.7.0
  - 'banking_platform >= 2.3.0, <= 2.4.1'
  - banking_platform = 2.6.2
  - banking_platform = 2.7.0
  - banking_platform = 2.7.1
  - blockchain_platform < 21.1.2
  - commerce_guided_search = 11.3.2
  - communications_application_session_controller = 3.9.0
  - communications_billing_and_revenue_management_elastic_charging_engine = 11.3
  - communications_billing_and_revenue_management_elastic_charging_engine = 12.0
  - communications_cloud_native_core_network_repository_function = 1.14.0
  - communications_cloud_native_core_policy = 1.14.0
  - communications_cloud_native_core_unified_data_repository = 1.4.0
  - communications_contacts_server = 8.0.0.6.0
  - communications_converged_application_server_-_service_controller = 6.2
  - communications_convergence = 3.0.2.2.0
  - 'communications_design_studio >= 7.4.0, <= 7.4.2'
  - communications_design_studio = 7.3.5
  - 'communications_diameter_intelligence_hub >= 8.0.0, <= 8.1.0'
  - 'communications_diameter_intelligence_hub >= 8.2.0, <= 8.2.3'
  - communications_interactive_session_recorder = 6.3
  - communications_interactive_session_recorder = 6.4
  - communications_offline_mediation_controller = 12.0.0.3
  - communications_order_and_service_management = 7.3
  - communications_order_and_service_management = 7.4
  - communications_policy_management = 12.5.0.0.0
  - communications_pricing_design_center = 12.0.0.4.0
  - communications_pricing_design_center = 12.0.0.5.0
  - communications_service_broker = 6.2
  - enterprise_communications_broker = 3.3
  - enterprise_session_border_controller = 8.4
  - enterprise_session_border_controller = 9.0
  - 'financial_services_analytical_applications_infrastructure >= 8.0.7, <= 8.1.1'
  - 'financial_services_model_management_and_governance >= 8.0.8, <= 8.1.1'
  - 'flexcube_core_banking >= 11.6.0, <= 11.8.0'
  - flexcube_core_banking = 5.2.0
  - flexcube_core_banking = 11.10.0
  - fusion_middleware_mapviewer = 12.2.1.4.0
  - health_sciences_data_management_workbench = 2.5.2.1
  - health_sciences_data_management_workbench = 3.0.0.0
  - 'health_sciences_information_manager >= 3.0.1, <= 3.0.4'
  - healthcare_data_repository = 8.1.0
  - helidon = 1.4.7
  - helidon = 2.2.0
  - insurance_policy_administration = 11.0.2
  - insurance_policy_administration = 11.1.0
  - insurance_policy_administration = 11.2.8
  - insurance_policy_administration = 11.3.0
  - insurance_policy_administration = 11.3.1
  - insurance_rules_palette = 11.0.2
  - insurance_rules_palette = 11.1.0
  - insurance_rules_palette = 11.2.8
  - insurance_rules_palette = 11.3.0
  - insurance_rules_palette = 11.3.1
  - oss_support_tools < 2.12.42
  - 'primavera_unifier >= 17.7, <= 17.12'
  - primavera_unifier = 18.8
  - primavera_unifier = 19.12
  - primavera_unifier = 20.12
  - primavera_unifier = 21.12
  - real_user_experience_insight = 13.4.1.0
  - real_user_experience_insight = 13.5.1.0
  - rest_data_services < 21.2
  - rest_data_services = 21.3
  - retail_assortment_planning = 16.0.3
  - 'retail_integration_bus >= 16.0.1, <= 16.0.3'
patched:
  - blockchain_platform 21.1.2
  - oss_support_tools 2.12.42
  - rest_data_services 21.2
published: '2021-04-13'
updated: '2026-08-25'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-29425'
references:
  - url: 'https://issues.apache.org/jira/browse/IO-556'
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r01b4a1fcdf3311c936ce33d75a9398b6c255f00c1a2f312ac21effe1%40%3Cnotifications.zookeeper.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r0bfa8f7921abdfae788b1f076a12f73a92c93cc0a6e1083bce0027c5%40%3Cnotifications.zookeeper.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r0d73e2071d1f1afe1a15da14c5b6feb2cf17e3871168d5a3c8451436%40%3Ccommits.pulsar.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r1c2f4683c35696cf6f863e3c107e37ec41305b1930dd40c17260de71%40%3Ccommits.pulsar.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r20416f39ca7f7344e7d76fe4d7063bb1d91ad106926626e7e83fb346%40%3Cnotifications.zookeeper.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r2345b49dbffa8a5c3c589c082fe39228a2c1d14f11b96c523da701db%40%3Cnotifications.zookeeper.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r2721aba31a8562639c4b937150897e24f78f747cdbda8641c0f659fe%40%3Cusers.kafka.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r27b1eedda37468256c4bb768fde1e8b79b37ec975cbbfd0d65a7ac34%40%3Cdev.myfaces.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r2bc986a070457daca457a54fe71ee09d2584c24dc262336ca32b6a19%40%3Cdev.creadur.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r2df50af2641d38f432ef025cd2ba5858215cc0cf3fc10396a674ad2e%40%3Cpluto-scm.portals.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r345330b7858304938b7b8029d02537a116d75265a598c98fa333504a%40%3Cdev.creadur.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r4050f9f6b42ebfa47a98cbdee4aabed4bb5fb8093db7dbb88faceba2%40%3Ccommits.zookeeper.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r462db908acc1e37c455e11b1a25992b81efd18e641e7e0ceb1b6e046%40%3Cnotifications.zookeeper.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r477c285126ada5c3b47946bb702cb222ac4e7fd3100c8549bdd6d3b2%40%3Cissues.zookeeper.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r47ab6f68cbba8e730f42c4ea752f3a44eb95fb09064070f2476bb401%40%3Cdev.creadur.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r5149f78be265be69d34eacb4e4b0fc7c9c697bcdfa91a1c1658d717b%40%3Cissues.zookeeper.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r523a6ffad58f71c4f3761e3cee72df878e48cdc89ebdce933be1475c%40%3Cdev.creadur.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r808be7d93b17a7055c1981a8453ae5f0d0fce5855407793c5d0ffffa%40%3Cuser.commons.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r8569a41d565ca880a4dee0e645dad1cd17ab4a92e68055ad9ebb7375%40%3Cdev.creadur.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r86528f4b7d222aed7891e7ac03d69a0db2a2dfa17b86ac3470d7f374%40%3Cnotifications.zookeeper.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r873d5ddafc0a68fd999725e559776dc4971d1ab39c0f5cc81bd9bc04%40%3Ccommits.pulsar.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r8bfc7235e6b39d90e6f446325a5a44c3e9e50da18860fdabcee23e29%40%3Cissues.zookeeper.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r8efcbabde973ea72f5e0933adc48ef1425db5cde850bf641b3993f31%40%3Cdev.commons.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r92ea904f4bae190b03bd42a4355ce3c2fbe8f36ab673e03f6ca3f9fa%40%3Cnotifications.zookeeper.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/ra8ef65aedc086d2d3d21492b4c08ae0eb8a3a42cc52e29ba1bc009d8%40%3Cdev.creadur.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/raa053846cae9d497606027816ae87b4e002b2e0eb66cb0dee710e1f5%40%3Cdev.creadur.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/rad4ae544747df32ccd58fff5a86cd556640396aeb161aa71dd3d192a%40%3Cuser.commons.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/rbebd3e19651baa7a4a5503a9901c95989df9d40602c8e35cb05d3eb5%40%3Cdev.creadur.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/rc10fa20ef4d13cbf6ebe0b06b5edb95466a1424a9b7673074ed03260%40%3Cnotifications.zookeeper.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/rc2dd3204260e9227a67253ef68b6f1599446005bfa0e1ddce4573a80%40%3Cpluto-dev.portals.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/rc359823b5500e9a9a2572678ddb8e01d3505a7ffcadfa8d13b8780ab%40%3Cuser.commons.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/rc5f3df5316c5237b78a3dff5ab95b311ad08e61d418cd992ca7e34ae%40%3Cnotifications.zookeeper.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/rc65f9bc679feffe4589ea0981ee98bc0af9139470f077a91580eeee0%40%3Cpluto-dev.portals.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/rca71a10ca533eb9bfac2d590533f02e6fb9064d3b6aa3ec90fdc4f51%40%3Cnotifications.zookeeper.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/rd09d4ab3e32e4b3a480e2ff6ff118712981ca82e817f28f2a85652a6%40%3Cnotifications.zookeeper.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/re41e9967bee064e7369411c28f0f5b2ad28b8334907c9c6208017279%40%3Cnotifications.zookeeper.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/red3aea910403d8620c73e1c7b9c9b145798d0469eb3298a7be7891af%40%3Cnotifications.zookeeper.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/rfa2f08b7c0caf80ca9f4a18bd875918fdd4e894e2ea47942a4589b9c%40%3Cdev.creadur.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/rfcd2c649c205f12b72dde044f905903460669a220a2eb7e12652d19d%40%3Cdev.zookeeper.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/rfd01af05babc95b8949e6d8ea78d9834699e1b06981040dde419a330%40%3Cdev.commons.apache.org%3E
    label: security@apache.org
  - url: 'https://lists.debian.org/debian-lts-announce/2021/08/msg00016.html'
    label: security@apache.org
  - url: 'https://security.netapp.com/advisory/ntap-20220210-0004/'
    label: security@apache.org
  - url: 'https://www.oracle.com/security-alerts/cpuapr2022.html'
    label: security@apache.org
  - url: 'https://www.oracle.com/security-alerts/cpujan2022.html'
    label: security@apache.org
  - url: 'https://www.oracle.com/security-alerts/cpujul2022.html'
    label: security@apache.org
  - url: 'https://www.oracle.com/security-alerts/cpuoct2021.html'
    label: security@apache.org
  - url: 'https://issues.apache.org/jira/browse/IO-556'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r01b4a1fcdf3311c936ce33d75a9398b6c255f00c1a2f312ac21effe1%40%3Cnotifications.zookeeper.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r0bfa8f7921abdfae788b1f076a12f73a92c93cc0a6e1083bce0027c5%40%3Cnotifications.zookeeper.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r0d73e2071d1f1afe1a15da14c5b6feb2cf17e3871168d5a3c8451436%40%3Ccommits.pulsar.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r1c2f4683c35696cf6f863e3c107e37ec41305b1930dd40c17260de71%40%3Ccommits.pulsar.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r20416f39ca7f7344e7d76fe4d7063bb1d91ad106926626e7e83fb346%40%3Cnotifications.zookeeper.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r2345b49dbffa8a5c3c589c082fe39228a2c1d14f11b96c523da701db%40%3Cnotifications.zookeeper.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r2721aba31a8562639c4b937150897e24f78f747cdbda8641c0f659fe%40%3Cusers.kafka.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r27b1eedda37468256c4bb768fde1e8b79b37ec975cbbfd0d65a7ac34%40%3Cdev.myfaces.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r2bc986a070457daca457a54fe71ee09d2584c24dc262336ca32b6a19%40%3Cdev.creadur.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r2df50af2641d38f432ef025cd2ba5858215cc0cf3fc10396a674ad2e%40%3Cpluto-scm.portals.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r345330b7858304938b7b8029d02537a116d75265a598c98fa333504a%40%3Cdev.creadur.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r4050f9f6b42ebfa47a98cbdee4aabed4bb5fb8093db7dbb88faceba2%40%3Ccommits.zookeeper.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r462db908acc1e37c455e11b1a25992b81efd18e641e7e0ceb1b6e046%40%3Cnotifications.zookeeper.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r477c285126ada5c3b47946bb702cb222ac4e7fd3100c8549bdd6d3b2%40%3Cissues.zookeeper.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r47ab6f68cbba8e730f42c4ea752f3a44eb95fb09064070f2476bb401%40%3Cdev.creadur.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r5149f78be265be69d34eacb4e4b0fc7c9c697bcdfa91a1c1658d717b%40%3Cissues.zookeeper.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r523a6ffad58f71c4f3761e3cee72df878e48cdc89ebdce933be1475c%40%3Cdev.creadur.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r808be7d93b17a7055c1981a8453ae5f0d0fce5855407793c5d0ffffa%40%3Cuser.commons.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r8569a41d565ca880a4dee0e645dad1cd17ab4a92e68055ad9ebb7375%40%3Cdev.creadur.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r86528f4b7d222aed7891e7ac03d69a0db2a2dfa17b86ac3470d7f374%40%3Cnotifications.zookeeper.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r873d5ddafc0a68fd999725e559776dc4971d1ab39c0f5cc81bd9bc04%40%3Ccommits.pulsar.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r8bfc7235e6b39d90e6f446325a5a44c3e9e50da18860fdabcee23e29%40%3Cissues.zookeeper.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r8efcbabde973ea72f5e0933adc48ef1425db5cde850bf641b3993f31%40%3Cdev.commons.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r92ea904f4bae190b03bd42a4355ce3c2fbe8f36ab673e03f6ca3f9fa%40%3Cnotifications.zookeeper.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/ra8ef65aedc086d2d3d21492b4c08ae0eb8a3a42cc52e29ba1bc009d8%40%3Cdev.creadur.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/raa053846cae9d497606027816ae87b4e002b2e0eb66cb0dee710e1f5%40%3Cdev.creadur.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rad4ae544747df32ccd58fff5a86cd556640396aeb161aa71dd3d192a%40%3Cuser.commons.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rbebd3e19651baa7a4a5503a9901c95989df9d40602c8e35cb05d3eb5%40%3Cdev.creadur.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rc10fa20ef4d13cbf6ebe0b06b5edb95466a1424a9b7673074ed03260%40%3Cnotifications.zookeeper.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rc2dd3204260e9227a67253ef68b6f1599446005bfa0e1ddce4573a80%40%3Cpluto-dev.portals.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rc359823b5500e9a9a2572678ddb8e01d3505a7ffcadfa8d13b8780ab%40%3Cuser.commons.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rc5f3df5316c5237b78a3dff5ab95b311ad08e61d418cd992ca7e34ae%40%3Cnotifications.zookeeper.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rc65f9bc679feffe4589ea0981ee98bc0af9139470f077a91580eeee0%40%3Cpluto-dev.portals.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rca71a10ca533eb9bfac2d590533f02e6fb9064d3b6aa3ec90fdc4f51%40%3Cnotifications.zookeeper.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rd09d4ab3e32e4b3a480e2ff6ff118712981ca82e817f28f2a85652a6%40%3Cnotifications.zookeeper.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/re41e9967bee064e7369411c28f0f5b2ad28b8334907c9c6208017279%40%3Cnotifications.zookeeper.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/red3aea910403d8620c73e1c7b9c9b145798d0469eb3298a7be7891af%40%3Cnotifications.zookeeper.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rfa2f08b7c0caf80ca9f4a18bd875918fdd4e894e2ea47942a4589b9c%40%3Cdev.creadur.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rfcd2c649c205f12b72dde044f905903460669a220a2eb7e12652d19d%40%3Cdev.zookeeper.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rfd01af05babc95b8949e6d8ea78d9834699e1b06981040dde419a330%40%3Cdev.commons.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2021/08/msg00016.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20220210-0004/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuapr2022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujan2022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujul2022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuoct2021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-29425.json
  - url: 'https://access.redhat.com/security/cve/CVE-2021-29425'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=1948752'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2021-29425'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2021-29425'
  - url: 'https://access.redhat.com/errata/RHSA-2021:3466'
  - url: 'https://access.redhat.com/errata/RHSA-2021:3467'
  - url: 'https://access.redhat.com/errata/RHSA-2021:3656'
  - url: 'https://access.redhat.com/errata/RHSA-2021:3468'
  - url: 'https://access.redhat.com/errata/RHSA-2021:3658'
  - url: 'https://access.redhat.com/errata/RHSA-2021:3471'
  - url: 'https://access.redhat.com/errata/RHSA-2022:1110'
  - url: 'https://access.redhat.com/errata/RHSA-2022:1108'
  - url: 'https://access.redhat.com/errata/RHSA-2021:3700'
  - url: 'https://access.redhat.com/errata/RHSA-2021:3225'
  - url: 'https://access.redhat.com/errata/RHSA-2021:3516'
  - url: 'https://access.redhat.com/errata/RHSA-2021:5134'
  - url: 'https://access.redhat.com/errata/RHSA-2021:3660'
  - url: 'https://access.redhat.com/errata/RHSA-2021:3534'
  - url: 'https://access.redhat.com/errata/RHSA-2021:2465'
tags:
  - nvd
  - exploit-available
  - csaf
  - vex
  - red-hat
epss: 0.09905
epssPercentile: 0.9541
ingestedAt: '2026-08-25T17:29:31.210Z'
exploits:
  github: 2
  githubRepos:
    - 'https://github.com/arsalanraja987/java-cve-2021-29425-tika-xxe'
    - 'https://github.com/shoucheng3/asf__commons-io_CVE-2021-29425_2-6'
  checkedAt: '2026-09-25T08:20:38.461Z'
exploitAvailable: true
---

## Overview

In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to construct a path value.

## Affected

- `commons_io = 2.2`
- `commons_io = 2.3`
- `commons_io = 2.4`
- `commons_io = 2.5`
- `commons_io = 2.6`
- `debian_linux = 9.0`
- `access_manager = 11.1.2.3.0`
- `access_manager = 12.2.1.3.0`
- `access_manager = 12.2.1.4.0`
- `agile_engineering_data_management = 6.2.1.0`
- `agile_product_lifecycle_management = 9.3.6`
- `application_performance_management = 13.4.1.0`
- `application_performance_management = 13.5.1.0`
- `application_testing_suite = 13.3.0.1`
- `banking_apis = 18.1`
- `banking_apis = 18.2`
- `banking_apis = 18.3`
- `banking_apis = 19.1`
- `banking_apis = 19.2`
- `banking_apis = 20.1`
- `banking_apis = 21.1`
- `banking_digital_experience = 17.2`
- `banking_digital_experience = 18.1`
- `banking_digital_experience = 18.3`
- `banking_digital_experience = 19.1`
- `banking_digital_experience = 19.2`
- `banking_digital_experience = 20.1`
- `banking_digital_experience = 21.1`
- `banking_enterprise_default_management = 2.6.2`
- `banking_enterprise_default_management = 2.7.0`
- `banking_enterprise_default_management = 2.7.1`
- `banking_enterprise_default_management = 2.10.0`
- `banking_enterprise_default_management = 2.12.0`
- `banking_enterprise_default_managment >= 2.3.0, <= 2.4.0`
- `banking_party_management = 2.7.0`
- `banking_platform >= 2.3.0, <= 2.4.1`
- `banking_platform = 2.6.2`
- `banking_platform = 2.7.0`
- `banking_platform = 2.7.1`
- `blockchain_platform < 21.1.2`
- `commerce_guided_search = 11.3.2`
- `communications_application_session_controller = 3.9.0`
- `communications_billing_and_revenue_management_elastic_charging_engine = 11.3`
- `communications_billing_and_revenue_management_elastic_charging_engine = 12.0`
- `communications_cloud_native_core_network_repository_function = 1.14.0`
- `communications_cloud_native_core_policy = 1.14.0`
- `communications_cloud_native_core_unified_data_repository = 1.4.0`
- `communications_contacts_server = 8.0.0.6.0`
- `communications_converged_application_server_-_service_controller = 6.2`
- `communications_convergence = 3.0.2.2.0`
- `communications_design_studio >= 7.4.0, <= 7.4.2`
- `communications_design_studio = 7.3.5`
- `communications_diameter_intelligence_hub >= 8.0.0, <= 8.1.0`
- `communications_diameter_intelligence_hub >= 8.2.0, <= 8.2.3`
- `communications_interactive_session_recorder = 6.3`
- `communications_interactive_session_recorder = 6.4`
- `communications_offline_mediation_controller = 12.0.0.3`
- `communications_order_and_service_management = 7.3`
- `communications_order_and_service_management = 7.4`
- `communications_policy_management = 12.5.0.0.0`
- `communications_pricing_design_center = 12.0.0.4.0`
- `communications_pricing_design_center = 12.0.0.5.0`
- `communications_service_broker = 6.2`
- `enterprise_communications_broker = 3.3`
- `enterprise_session_border_controller = 8.4`
- `enterprise_session_border_controller = 9.0`
- `financial_services_analytical_applications_infrastructure >= 8.0.7, <= 8.1.1`
- `financial_services_model_management_and_governance >= 8.0.8, <= 8.1.1`
- `flexcube_core_banking >= 11.6.0, <= 11.8.0`
- `flexcube_core_banking = 5.2.0`
- `flexcube_core_banking = 11.10.0`
- `fusion_middleware_mapviewer = 12.2.1.4.0`
- `health_sciences_data_management_workbench = 2.5.2.1`
- `health_sciences_data_management_workbench = 3.0.0.0`
- `health_sciences_information_manager >= 3.0.1, <= 3.0.4`
- `healthcare_data_repository = 8.1.0`
- `helidon = 1.4.7`
- `helidon = 2.2.0`
- `insurance_policy_administration = 11.0.2`
- `insurance_policy_administration = 11.1.0`
- `insurance_policy_administration = 11.2.8`
- `insurance_policy_administration = 11.3.0`
- `insurance_policy_administration = 11.3.1`
- `insurance_rules_palette = 11.0.2`
- `insurance_rules_palette = 11.1.0`
- `insurance_rules_palette = 11.2.8`
- `insurance_rules_palette = 11.3.0`
- `insurance_rules_palette = 11.3.1`
- `oss_support_tools < 2.12.42`
- `primavera_unifier >= 17.7, <= 17.12`
- `primavera_unifier = 18.8`
- `primavera_unifier = 19.12`
- `primavera_unifier = 20.12`
- `primavera_unifier = 21.12`
- `real_user_experience_insight = 13.4.1.0`
- `real_user_experience_insight = 13.5.1.0`
- `rest_data_services < 21.2`
- `rest_data_services = 21.3`
- `retail_assortment_planning = 16.0.3`
- `retail_integration_bus >= 16.0.1, <= 16.0.3`

## Remediation

Upgrade past the affected range:

- `blockchain_platform 21.1.2`
- `oss_support_tools 2.12.42`
- `rest_data_services 21.2`

## Vendor advisories

- **RHSA-2021:3466** · Red Hat · fixed in: Red Hat JBoss EAP 7.3 for RHEL 6 Server · released 2021-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2021:3466)
- **RHSA-2021:3467** · Red Hat · fixed in: Red Hat JBoss EAP 7.3 for RHEL 7 Server · released 2021-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2021:3467)
- **RHSA-2021:3656** · Red Hat · fixed in: Red Hat JBoss EAP 7.4 for RHEL 7 Server · released 2021-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2021:3656)
- **RHSA-2021:3468** · Red Hat · fixed in: Red Hat JBoss EAP 7.3 for BaseOS-8 · released 2021-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2021:3468)
- **RHSA-2021:3658** · Red Hat · fixed in: Red Hat JBoss EAP 7.4 for RHEL 8 · released 2021-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2021:3658)
- **RHSA-2021:3471** · Red Hat · fixed in: EAP 7.3.9 release · released 2021-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2021:3471)
- **RHSA-2022:1110** · Red Hat · fixed in: RHDM 7.12.1 · released 2022-03-29 · [advisory](https://access.redhat.com/errata/RHSA-2022:1110)
- **RHSA-2022:1108** · Red Hat · fixed in: RHPAM 7.12.1 · released 2022-03-29 · [advisory](https://access.redhat.com/errata/RHSA-2022:1108)
- **RHSA-2021:3700** · Red Hat · fixed in: Red Hat AMQ 7.9.0 · released 2021-09-30 · [advisory](https://access.redhat.com/errata/RHSA-2021:3700)
- **RHSA-2021:3225** · Red Hat · fixed in: Red Hat AMQ Streams 1.8.0 · released 2021-08-19 · [advisory](https://access.redhat.com/errata/RHSA-2021:3225)
- **RHSA-2021:3516** · Red Hat · fixed in: Red Hat EAP-XP 2.0.0 via EAP 7.3.x base · released 2021-09-13 · [advisory](https://access.redhat.com/errata/RHSA-2021:3516)
- **Red Hat VEX** · Moderate · affected: A-MQ Clients 2, Red Hat BPM Suite 6, Red Hat Data Grid 8, Red Hat Enterprise Linux 7, Red Hat JBoss A-MQ 6, Red Hat JBoss BRMS 6, … · no fix planned: Red Hat BPM Suite 6, Red Hat Enterprise Linux 7, Red Hat JBoss A-MQ 6, Red Hat JBoss BRMS 6, … · updated 2026-09-07 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-29425.json)
