CVE-2025-27553
HIGH7.5EPSS 0.71%commons-vfs - security update
發布日:2025/3/23修改日:2026/4/28
描述
Relative Path Traversal vulnerability in Apache Commons VFS before 2.10.0. The FileObject API in Commons VFS has a 'resolveFile' method that takes a 'scope' parameter. Specifying 'NameScope.DESCENDENT' promises that "an exception is thrown if the resolved file is not a descendent of the base file". However, when the path contains encoded ".." characters (for example, "%2E%2E/bar.txt"), it might return file objects that are not a descendent of the base file, without throwing an exception. This issue affects Apache Commons VFS: before 2.10.0. Users are recommended to upgrade to version 2.10.0, which fixes the issue.
受影響套件(3)
- Debian/commons-vfsfrom 0, < 2.1-2+deb11u1
- Debian/commons-vfsfrom 0, < 2.1-2+deb11u1
- Maven/org.apache.commons:commons-vfs2from 0, < 2.10.0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
參考連結(6)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2025-27553
- ADVISORYhttps://security-tracker.debian.org/tracker/CVE-2025-27553
- PATCHhttps://github.com/apache/commons-vfs
- WEBhttps://lists.apache.org/thread/cnzqowyw9r2pl263cylmxhnvh41hyjcb
- WEBhttps://lists.debian.org/debian-lts-announce/2025/04/msg00006.html
- WEBhttp://www.openwall.com/lists/oss-security/2025/03/23/1