[
https://issues.apache.org/jira/browse/IO-559?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16474394#comment-16474394
]
Gregg Yost commented on IO-559:
-------------------------------
Black Duck security scanning software is now reporting a vulnerability against
Commons IO 2.5 because of this. Like Maria in the prior comment, I'd like to
know if there's any feedback on this issue and how critical the Apache
community considers this. My customers are always uncomfortable seeing Black
Duck flagging vulnerabilities in the open source packages that we use, and I'd
rather not have to rewrite things to no longer use Commons IO.
> FilenameUtils.normalize should verify hostname syntax in UNC path
> -----------------------------------------------------------------
>
> Key: IO-559
> URL: https://issues.apache.org/jira/browse/IO-559
> Project: Commons IO
> Issue Type: Bug
> Components: Utilities
> Affects Versions: 2.6
> Reporter: Stefan Bodewig
> Priority: Major
>
> {{FilenameUtils.normalize}} will accept broken file names as UNC path even if
> their hostname part doesn't match the syntax of a proper hostname. Using
> certain hostnames like "." this may lead to strange side effects.
> Most likely the best fix will be to make {{getPrefixLength}} verify the
> hostname part of a suspected UNC path and return a value of {{NOT_FOUND}} if
> it is not a valid hostname - much like it does for triple slashes.
--
This message was sent by Atlassian JIRA
(v7.6.3#76005)