Apache Commons IO是美国阿帕奇(Apache)基金会的一个应用程序。提供一个帮助开发IO功能。 Apache Commons IO 2.2版本至2.6版本存在路径遍历漏洞,该漏洞源于当使用不正确的输入字符串(例如“ //../foo”或“ .. foo”)调用FileNameUtils.normalize方法时,则可能会提供对父目录中文件的访问权限。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache Commons IO | Apache Commons IO 2.2 |
affected |
Apache Commons IO 2.3 |
affected | ||
Apache Commons IO 2.4 |
affected | ||
Apache Commons IO 2.5 |
affected | ||
Apache Commons IO 2.6 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Commons IO | Apache Commons IO 2.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | None | https://github.com/arsalanraja987/java-cve-2021-29425-tika-xxe | POC Details |
| 2 | None | https://github.com/shoucheng3/asf__commons-io_CVE-2021-29425_2-6 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2021-27905 | SSRF vulnerability with the Replication handler | |
| CVE-2021-29262 | Misapplied Zookeeper ACLs can result in leakage of configured authentication and authoriza | |
| CVE-2021-29943 | Apache Solr Unprivileged users may be able to perform unauthorized read/write to collectio |
No comments yet