Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-29425

24
FAUCET Score

CVE-2021-29425 is a limited path traversal vulnerability in Apache Commons IO versions prior to 2.7, affecting products like Apache, Debian, NetApp, and Oracle. An attacker could exploit this by providing a specially crafted input string to FileNameUtils.normalize, potentially gaining limited access to files in a parent directory. The vulnerability has a CVSS score of 4.8 (Medium), indicating a network-based attack with high complexity, resulting in low confidentiality and integrity impacts. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
2.2CPE matchmatch criteria
cpe:2.3:a:apache:commons_io:2.2:-:*:*:*:*:*:*
2.3CPE matchmatch criteria
cpe:2.3:a:apache:commons_io:2.3:-:*:*:*:*:*:*
2.4CPE matchmatch criteria
cpe:2.3:a:apache:commons_io:2.4:-:*:*:*:*:*:*
2.5CPE matchmatch criteria
cpe:2.3:a:apache:commons_io:2.5:-:*:*:*:*:*:*
2.6CPE matchmatch criteria
cpe:2.3:a:apache:commons_io:2.6:-:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

4.8MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
2.2
Impact Score
2.5
CvssVersion
3.1

Exploit Intelligence

EPSS Score
10.23%
Probability of exploitation in next 30 days
EPSS Percentile
95.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.1023 is in the 95th percentile among its peer group of 19,958 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (61)

mavenpatch availablevia ghsa
Product: commons-io:commons-ioFixed in: 2.7
mavenpatch availablevia ghsa
Product: org.checkerframework.annotatedlib:commons-ioFixed in: 2.7
oraclepatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat AMQ Streams 1.8.0Fixed in: commons-io
View patch
redhatpatch availablevia redhat_api
Product: Red Hat EAP-XP 2.0.0 via EAP 7.3.x baseFixed in: commons-io
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Fuse 7.10Fixed in: commons-io
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7Fixed in: commons-io
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6Fixed in: eap7-apache-commons-io-0:2.10.0-1.redhat_00001.1.el6eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6Fixed in: eap7-hal-console-0:3.2.16-1.Final_redhat_00001.1.el6eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6Fixed in: eap7-hibernate-0:5.3.20-4.SP2_redhat_00001.1.el6eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6Fixed in: eap7-ironjacamar-0:1.4.35-1.Final_redhat_00001.1.el6eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6Fixed in: eap7-jakarta-el-0:3.0.3-2.redhat_00006.1.el6eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6Fixed in: eap7-jberet-0:1.3.9-1.Final_redhat_00001.1.el6eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6Fixed in: eap7-jboss-remoting-0:5.0.23-2.SP1_redhat_00001.1.el6eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6Fixed in: eap7-jboss-server-migration-0:1.7.2-9.Final_redhat_00010.1.el6eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6Fixed in: eap7-narayana-0:5.9.12-1.Final_redhat_00001.1.el6eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6Fixed in: eap7-picketbox-0:5.0.3-9.Final_redhat_00008.1.el6eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6Fixed in: eap7-undertow-0:2.0.39-1.SP2_redhat_00001.1.el6eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6Fixed in: eap7-wildfly-0:7.3.9-2.GA_redhat_00002.1.el6eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6Fixed in: eap7-wildfly-http-client-0:1.0.29-1.Final_redhat_00002.1.el6eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6Fixed in: eap7-wildfly-transaction-client-0:1.1.14-2.Final_redhat_00001.1.el6eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7Fixed in: eap7-apache-commons-io-0:2.10.0-1.redhat_00001.1.el7eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7Fixed in: eap7-hal-console-0:3.2.16-1.Final_redhat_00001.1.el7eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7Fixed in: eap7-hibernate-0:5.3.20-4.SP2_redhat_00001.1.el7eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7Fixed in: eap7-ironjacamar-0:1.4.35-1.Final_redhat_00001.1.el7eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7Fixed in: eap7-jakarta-el-0:3.0.3-2.redhat_00006.1.el7eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7Fixed in: eap7-jberet-0:1.3.9-1.Final_redhat_00001.1.el7eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7Fixed in: eap7-jboss-remoting-0:5.0.23-2.SP1_redhat_00001.1.el7eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7Fixed in: eap7-jboss-server-migration-0:1.7.2-9.Final_redhat_00010.1.el7eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7Fixed in: eap7-narayana-0:5.9.12-1.Final_redhat_00001.1.el7eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7Fixed in: eap7-picketbox-0:5.0.3-9.Final_redhat_00008.1.el7eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7Fixed in: eap7-undertow-0:2.0.39-1.SP2_redhat_00001.1.el7eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7Fixed in: eap7-wildfly-0:7.3.9-2.GA_redhat_00002.1.el7eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7Fixed in: eap7-wildfly-http-client-0:1.0.29-1.Final_redhat_00002.1.el7eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7Fixed in: eap7-wildfly-transaction-client-0:1.1.14-2.Final_redhat_00001.1.el7eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8Fixed in: eap7-apache-commons-io-0:2.10.0-1.redhat_00001.1.el8eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8Fixed in: eap7-hal-console-0:3.2.16-1.Final_redhat_00001.1.el8eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8Fixed in: eap7-hibernate-0:5.3.20-4.SP2_redhat_00001.1.el8eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8Fixed in: eap7-ironjacamar-0:1.4.35-1.Final_redhat_00001.1.el8eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8Fixed in: eap7-jakarta-el-0:3.0.3-2.redhat_00006.1.el8eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8Fixed in: eap7-jberet-0:1.3.9-1.Final_redhat_00001.1.el8eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8Fixed in: eap7-jboss-remoting-0:5.0.23-2.SP1_redhat_00001.1.el8eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8Fixed in: eap7-jboss-server-migration-0:1.7.2-9.Final_redhat_00010.1.el8eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8Fixed in: eap7-narayana-0:5.9.12-1.Final_redhat_00001.1.el8eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8Fixed in: eap7-undertow-0:2.0.39-1.SP2_redhat_00001.1.el8eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8Fixed in: eap7-wildfly-0:7.3.9-2.GA_redhat_00002.1.el8eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8Fixed in: eap7-wildfly-http-client-0:1.0.29-1.Final_redhat_00002.1.el8eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8Fixed in: eap7-wildfly-transaction-client-0:1.1.14-2.Final_redhat_00001.1.el8eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8Fixed in: eap7-apache-commons-io-0:2.10.0-1.redhat_00001.1.el8eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7Fixed in: eap7-apache-commons-io-0:2.10.0-1.redhat_00001.1.el7eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Single Sign-On 7.4.9Fixed in: commons-io
View patch
redhatpatch availablevia redhat_api
Product: RHDM 7.12.1Fixed in: commons-io
View patch
redhatpatch availablevia redhat_api
Product: RHPAM 7.12.1Fixed in: commons-io
View patch
redhatpatch availablevia redhat_api
Product: Vert.x 4.1.0Fixed in: commons-io
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8Fixed in: eap7-picketbox-0:5.0.3-9.Final_redhat_00008.1.el8eap
View patch
redhatpatch availablevia redhat_api
Product: EAP 7.3.9 releaseFixed in: commons-io
View patch
redhatpatch availablevia redhat_api
Product: Red Hat AMQ 7.9.0Fixed in: commons-io
View patch
redhatend of lifevia redhat_api
Product: A-MQ Clients 2Fixed in: commons-io
redhatend of lifevia redhat_api
Product: Red Hat Data Grid 8Fixed in: commons-io
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Application RuntimesFixed in: commons-io
redhatend of lifevia redhat_api
Product: Red Hat Software CollectionsFixed in: rh-maven36-apache-commons-io

Vendor Advisories (2)

mavenGHSA-gwrp-pvrq-jmwvmedium

Path Traversal and Improper Input Validation in Apache Commons IO

Apr 26, 2021
redhatCVE-2021-29425Moderate

apache-commons-io: Limited path traversal in Apache Commons IO 2.2 to 2.6

Apr 12, 2021

References

issues.apache.org / jira/browse/IO-556
ExploitIssue TrackingVendor Advisory
lists.apache.org / thread.html/r01b4a1fcdf3311c936ce33d75a9398b6c255f00c1a2f312ac21effe1%40%3Cnotifications.zookeeper.apache.org%3E
lists.apache.org / thread.html/r0bfa8f7921abdfae788b1f076a12f73a92c93cc0a6e1083bce0027c5%40%3Cnotifications.zookeeper.apache.org%3E
lists.apache.org / thread.html/r0d73e2071d1f1afe1a15da14c5b6feb2cf17e3871168d5a3c8451436%40%3Ccommits.pulsar.apache.org%3E
lists.apache.org / thread.html/r1c2f4683c35696cf6f863e3c107e37ec41305b1930dd40c17260de71%40%3Ccommits.pulsar.apache.org%3E
lists.apache.org / thread.html/r20416f39ca7f7344e7d76fe4d7063bb1d91ad106926626e7e83fb346%40%3Cnotifications.zookeeper.apache.org%3E
lists.apache.org / thread.html/r2345b49dbffa8a5c3c589c082fe39228a2c1d14f11b96c523da701db%40%3Cnotifications.zookeeper.apache.org%3E
lists.apache.org / thread.html/r2721aba31a8562639c4b937150897e24f78f747cdbda8641c0f659fe%40%3Cusers.kafka.apache.org%3E
lists.apache.org / thread.html/r27b1eedda37468256c4bb768fde1e8b79b37ec975cbbfd0d65a7ac34%40%3Cdev.myfaces.apache.org%3E
lists.apache.org / thread.html/r2bc986a070457daca457a54fe71ee09d2584c24dc262336ca32b6a19%40%3Cdev.creadur.apache.org%3E
lists.apache.org / thread.html/r2df50af2641d38f432ef025cd2ba5858215cc0cf3fc10396a674ad2e%40%3Cpluto-scm.portals.apache.org%3E
lists.apache.org / thread.html/r345330b7858304938b7b8029d02537a116d75265a598c98fa333504a%40%3Cdev.creadur.apache.org%3E
lists.apache.org / thread.html/r4050f9f6b42ebfa47a98cbdee4aabed4bb5fb8093db7dbb88faceba2%40%3Ccommits.zookeeper.apache.org%3E
lists.apache.org / thread.html/r462db908acc1e37c455e11b1a25992b81efd18e641e7e0ceb1b6e046%40%3Cnotifications.zookeeper.apache.org%3E
lists.apache.org / thread.html/r477c285126ada5c3b47946bb702cb222ac4e7fd3100c8549bdd6d3b2%40%3Cissues.zookeeper.apache.org%3E
lists.apache.org / thread.html/r47ab6f68cbba8e730f42c4ea752f3a44eb95fb09064070f2476bb401%40%3Cdev.creadur.apache.org%3E
lists.apache.org / thread.html/r5149f78be265be69d34eacb4e4b0fc7c9c697bcdfa91a1c1658d717b%40%3Cissues.zookeeper.apache.org%3E
lists.apache.org / thread.html/r523a6ffad58f71c4f3761e3cee72df878e48cdc89ebdce933be1475c%40%3Cdev.creadur.apache.org%3E
lists.apache.org / thread.html/r808be7d93b17a7055c1981a8453ae5f0d0fce5855407793c5d0ffffa%40%3Cuser.commons.apache.org%3E
lists.apache.org / thread.html/r8569a41d565ca880a4dee0e645dad1cd17ab4a92e68055ad9ebb7375%40%3Cdev.creadur.apache.org%3E
lists.apache.org / thread.html/r86528f4b7d222aed7891e7ac03d69a0db2a2dfa17b86ac3470d7f374%40%3Cnotifications.zookeeper.apache.org%3E
lists.apache.org / thread.html/r873d5ddafc0a68fd999725e559776dc4971d1ab39c0f5cc81bd9bc04%40%3Ccommits.pulsar.apache.org%3E
lists.apache.org / thread.html/r8bfc7235e6b39d90e6f446325a5a44c3e9e50da18860fdabcee23e29%40%3Cissues.zookeeper.apache.org%3E
lists.apache.org / thread.html/r8efcbabde973ea72f5e0933adc48ef1425db5cde850bf641b3993f31%40%3Cdev.commons.apache.org%3E
lists.apache.org / thread.html/r92ea904f4bae190b03bd42a4355ce3c2fbe8f36ab673e03f6ca3f9fa%40%3Cnotifications.zookeeper.apache.org%3E
lists.apache.org / thread.html/ra8ef65aedc086d2d3d21492b4c08ae0eb8a3a42cc52e29ba1bc009d8%40%3Cdev.creadur.apache.org%3E
lists.apache.org / thread.html/raa053846cae9d497606027816ae87b4e002b2e0eb66cb0dee710e1f5%40%3Cdev.creadur.apache.org%3E
lists.apache.org / thread.html/rad4ae544747df32ccd58fff5a86cd556640396aeb161aa71dd3d192a%40%3Cuser.commons.apache.org%3E
lists.apache.org / thread.html/rbebd3e19651baa7a4a5503a9901c95989df9d40602c8e35cb05d3eb5%40%3Cdev.creadur.apache.org%3E
lists.apache.org / thread.html/rc10fa20ef4d13cbf6ebe0b06b5edb95466a1424a9b7673074ed03260%40%3Cnotifications.zookeeper.apache.org%3E
lists.apache.org / thread.html/rc2dd3204260e9227a67253ef68b6f1599446005bfa0e1ddce4573a80%40%3Cpluto-dev.portals.apache.org%3E
lists.apache.org / thread.html/rc359823b5500e9a9a2572678ddb8e01d3505a7ffcadfa8d13b8780ab%40%3Cuser.commons.apache.org%3E
Mailing ListVendor Advisory
lists.apache.org / thread.html/rc5f3df5316c5237b78a3dff5ab95b311ad08e61d418cd992ca7e34ae%40%3Cnotifications.zookeeper.apache.org%3E
lists.apache.org / thread.html/rc65f9bc679feffe4589ea0981ee98bc0af9139470f077a91580eeee0%40%3Cpluto-dev.portals.apache.org%3E
lists.apache.org / thread.html/rca71a10ca533eb9bfac2d590533f02e6fb9064d3b6aa3ec90fdc4f51%40%3Cnotifications.zookeeper.apache.org%3E
lists.apache.org / thread.html/rd09d4ab3e32e4b3a480e2ff6ff118712981ca82e817f28f2a85652a6%40%3Cnotifications.zookeeper.apache.org%3E
lists.apache.org / thread.html/re41e9967bee064e7369411c28f0f5b2ad28b8334907c9c6208017279%40%3Cnotifications.zookeeper.apache.org%3E
lists.apache.org / thread.html/red3aea910403d8620c73e1c7b9c9b145798d0469eb3298a7be7891af%40%3Cnotifications.zookeeper.apache.org%3E
lists.apache.org / thread.html/rfa2f08b7c0caf80ca9f4a18bd875918fdd4e894e2ea47942a4589b9c%40%3Cdev.creadur.apache.org%3E
lists.apache.org / thread.html/rfcd2c649c205f12b72dde044f905903460669a220a2eb7e12652d19d%40%3Cdev.zookeeper.apache.org%3E
lists.apache.org / thread.html/rfd01af05babc95b8949e6d8ea78d9834699e1b06981040dde419a330%40%3Cdev.commons.apache.org%3E
lists.debian.org / debian-lts-announce/2021/08/msg00016.html
Mailing ListThird Party Advisory
security.netapp.com / advisory/ntap-20220210-0004
Third Party Advisory
oracle.com / security-alerts/cpuapr2022.html
PatchThird Party Advisory
oracle.com / security-alerts/cpujan2022.html
PatchThird Party Advisory
oracle.com / security-alerts/cpujul2022.html
PatchThird Party Advisory
oracle.com / security-alerts/cpuoct2021.html
Third Party Advisory