Skip to content

Commit d3970c6

Browse files
committed
Document CVEs fixed in 2.10.0
- CVE-2025-27553 Apache Commons VFS: Possible path traversal issue when using NameScope.DESCENDENT - CVE-2025-30474 Apache Commons VFS: Failing to find an FTP file can reveal the URI's password in an error message
1 parent 409061a commit d3970c6

File tree

1 file changed

+6
-2
lines changed

1 file changed

+6
-2
lines changed

Diff for: src/site/xdoc/security.xml

+6-2
Original file line numberDiff line numberDiff line change
@@ -45,7 +45,11 @@
4545
</p>
4646
</section>
4747
<section name="Security Vulnerabilities">
48-
<p>None.</p>
48+
<p>The following have been fixed in 2.10.0:</p>
49+
<ul>
50+
<li><a href="https://www.cve.org/CVERecord?id=CVE-2025-27553">CVE-2025-27553</a>: Apache Commons VFS: Possible path traversal issue when using NameScope.DESCENDENT</li>
51+
<li><a href="https://www.cve.org/CVERecord?id=CVE-2025-30474">CVE-2025-30474</a>: Apache Commons VFS: Failing to find an FTP file can reveal the URI's password in an error message</li>
52+
</ul>
4953
</section>
5054
</body>
51-
</document>
55+
</document>

0 commit comments

Comments
 (0)