漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Apache Commons VFS: Possible path traversal issue when using NameScope.DESCENDENT
Vulnerability Description
Relative Path Traversal vulnerability in Apache Commons VFS before 2.10.0. The FileObject API in Commons VFS has a 'resolveFile' method that takes a 'scope' parameter. Specifying 'NameScope.DESCENDENT' promises that "an exception is thrown if the resolved file is not a descendent of the base file". However, when the path contains encoded ".." characters (for example, "%2E%2E/bar.txt"), it might return file objects that are not a descendent of the base file, without throwing an exception. This issue affects Apache Commons VFS: before 2.10.0. Users are recommended to upgrade to version 2.10.0, which fixes the issue.
CVSS Information
N/A
Vulnerability Type
相对路径遍历
Vulnerability Title
Apache Commons VFS 安全漏洞
Vulnerability Description
Apache Commons VFS是美国阿帕奇(Apache)基金会的一个公共虚拟文件系统。 Apache Commons VFS 2.10.0之前版本存在安全漏洞,该漏洞源于相对路径遍历,可能导致返回非基础文件后代的文件对象。
CVSS Information
N/A
Vulnerability Type
N/A