#VU52252 Path traversal in Apache Commons IO - CVE-2021-29425
Published: April 15, 2021
Apache Commons IO
Apache Foundation
Description
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error within the FileNameUtils.normalize method when processing directory traversal sequences, such as "//../foo", or "\..foo". A remote attacker can send a specially crafted request and verify files availability in the parent folder.