📦 Commons Vfs

by Apache

🔍 What is Commons Vfs?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-27553

HIGH CVSS 7.5 Mar 23, 2025

This CVE describes a path traversal vulnerability in Apache Commons VFS where encoded '..' sequences (%2E%2E) bypass the NameScope.DESCENDENT validation in the resolveFile method. This allows attacker...

CVE-2025-30474

MEDIUM CVSS 5.0 Mar 23, 2025

Apache Commons VFS versions before 2.10.0 can leak FTP passwords in error messages when file operations fail. This occurs because the FtpFileObject class includes the full URI (including credentials) ...