commons-io:commons-io@2.0.1 vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the commons-io:commons-io package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Directory Traversal

commons-io:commons-io is a The Apache Commons IO library contains utility classes, stream implementations, file filters, file comparators, endian transformation classes, and much more.

Affected versions of this package are vulnerable to Directory Traversal via calling the method FileNameUtils.normalize using an improper string like //../foo or \\..\foo, which may allow access to files in the parent directory.

How to fix Directory Traversal?

Upgrade commons-io:commons-io to version 2.7 or higher.

[0,2.7)