<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 12:01:12 +0000</lastBuildDate>
    <item>
      <title>bdu:2021-02220</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2021-02220</link>
      <description>bdu:2021-02220</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2021-02220</guid>
    </item>
    <item>
      <title>certfr-2021-avi-474 — De multiples vulnérabilités ont été découvertes dans les produits IBM.
Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2021-avi-474</link>
      <description>certfr-2021-avi-474</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2021-avi-474</guid>
    </item>
    <item>
      <title>cnvd-2021-30583</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2021-30583</link>
      <description>cnvd-2021-30583</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2021-30583</guid>
    </item>
    <item>
      <title>EUVD-2026-26327</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-26327</link>
      <description>EUVD-2026-26327</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-26327</guid>
    </item>
    <item>
      <title>fkie_cve-2021-29425</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-29425</link>
      <description>&lt;p&gt;In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like &amp;#34;//../foo&amp;#34;, or &amp;#34;\\..\foo&amp;#34;, the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus &amp;#34;limited&amp;#34; path traversal), if the calling code would use the result to construct a path value.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like &amp;#34;//../foo&amp;#34;, or &amp;#34;\\..\foo&amp;#34;, the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus &amp;#34;limited&amp;#34; path traversal), if the calling code would use the result to construct a path value.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-29425</guid>
    </item>
    <item>
      <title>GHSA-gwrp-pvrq-jmwv — Path Traversal and Improper Input Validation in Apache Commons IO</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gwrp-pvrq-jmwv</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: commons-io:commons-io, Maven: com.cosium.vet:vet, Maven: com.diamondq.common:common-thirdparty.jcasbin, Maven: com.liferay:com.liferay.sass.compiler.jsass, Maven: com.virjar:ratel-api, Maven: net.hasor:cobble-lang, Maven: org.apache.commons:commons-io, Maven: org.apache.servicemix.bundles:org.apache.servicemix.bundles.commons-io, Maven: org.checkerframework.annotatedlib:commons-io, Maven: org.smartboot.servlet:servlet-core&lt;/p&gt;
&lt;p&gt;In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like &amp;#34;//../foo&amp;#34;, or &amp;#34;\\..\foo&amp;#34;, the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus &amp;#34;limited&amp;#34; path traversal), if the calling code would use the result to construct a path value.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: commons-io:commons-io, Maven: com.cosium.vet:vet, Maven: com.diamondq.common:common-thirdparty.jcasbin, Maven: com.liferay:com.liferay.sass.compiler.jsass, Maven: com.virjar:ratel-api, Maven: net.hasor:cobble-lang, Maven: org.apache.commons:commons-io, Maven: org.apache.servicemix.bundles:org.apache.servicemix.bundles.commons-io, Maven: org.checkerframework.annotatedlib:commons-io, Maven: org.smartboot.servlet:servlet-core&lt;/p&gt;
&lt;p&gt;In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like &amp;#34;//../foo&amp;#34;, or &amp;#34;\\..\foo&amp;#34;, the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus &amp;#34;limited&amp;#34; path traversal), if the calling code would use the result to construct a path value.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gwrp-pvrq-jmwv</guid>
    </item>
    <item>
      <title>gsd-2021-29425</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-29425</link>
      <description>gsd-2021-29425</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-29425</guid>
    </item>
    <item>
      <title>OESA-2021-1182 — apache-commons-io security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2021-1182</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: apache-commons-io&lt;/p&gt;
&lt;p&gt;Apache commons IO library is used for developing IO functionality. It contains a collecton of utilities with utility classes, stream implementations, file filters, file comparators, endian transformation classes, and much more.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like //../foo , or .. foo , the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus limited path traversal), if the calling code would use the result to construct a path value.(CVE-2021-29425)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: apache-commons-io&lt;/p&gt;
&lt;p&gt;Apache commons IO library is used for developing IO functionality. It contains a collecton of utilities with utility classes, stream implementations, file filters, file comparators, endian transformation classes, and much more.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like //../foo , or .. foo , the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus limited path traversal), if the calling code would use the result to construct a path value.(CVE-2021-29425)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2021-1182</guid>
    </item>
    <item>
      <title>openSUSE-SU-2021:0605-1 — Security update for apache-commons-io</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2021:0605-1</link>
      <description>&lt;p&gt;Security update for apache-commons-io&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for apache-commons-io&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2021:0605-1</guid>
    </item>
    <item>
      <title>RHSA-2021:2465 — Red Hat Security Advisory: Red Hat build of Eclipse Vert.x 4.1.0 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:2465</link>
      <description>&lt;p&gt;netty: Request smuggling via content-length header apache-commons-io: Limited path traversal in Apache Commons IO 2.2 to 2.6&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;netty: Request smuggling via content-length header apache-commons-io: Limited path traversal in Apache Commons IO 2.2 to 2.6&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:2465</guid>
    </item>
    <item>
      <title>SUSE-SU-2021:1282-1 — Security update for apache-commons-io</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2021:1282-1</link>
      <description>&lt;p&gt;Security update for apache-commons-io&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for apache-commons-io&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2021:1282-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-29425</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-29425</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: commons-io, Ubuntu:Pro:16.04:LTS: commons-io, Ubuntu:18.04:LTS: commons-io, Ubuntu:20.04:LTS: commons-io&lt;/p&gt;
&lt;p&gt;In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like &amp;#34;//../foo&amp;#34;, or &amp;#34;\\..\foo&amp;#34;, the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus &amp;#34;limited&amp;#34; path traversal), if the calling code would use the result to construct a path value.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: commons-io, Ubuntu:Pro:16.04:LTS: commons-io, Ubuntu:18.04:LTS: commons-io, Ubuntu:20.04:LTS: commons-io&lt;/p&gt;
&lt;p&gt;In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like &amp;#34;//../foo&amp;#34;, or &amp;#34;\\..\foo&amp;#34;, the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus &amp;#34;limited&amp;#34; path traversal), if the calling code would use the result to construct a path value.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-29425</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-0119 — Oracle Utilities Applications: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0119</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Oracle Utilities Applications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Oracle Utilities Applications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0119</guid>
    </item>
  </channel>
</rss>
