This update for apache-commons-vfs2 fixes the following issues:
* CVE-2025-27553: Fixed possible path traversal issue when using
NameScope.DESCENDENT (bsc#1239973)
* CVE-2025-30474: Fixed information disclosure due to failing to find an FTP
file reveal the URI's password in an error message (bsc#1239974)
Other fixes: \- Upgrade to upstream version 2.10.0
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* openSUSE Leap 15.6
zypper in -t patch openSUSE-SLE-15.6-2025-1022=1
* openSUSE Leap 15.6 (noarch)
* apache-commons-vfs2-ant-2.10.0-150200.3.3.1
* apache-commons-vfs2-javadoc-2.10.0-150200.3.3.1
* apache-commons-vfs2-examples-2.10.0-150200.3.3.1
* apache-commons-vfs2-2.10.0-150200.3.3.1
* bsc#1239973
* bsc#1239974
## References:
* https://www.suse.com/security/cve/CVE-2025-27553.html
* https://www.suse.com/security/cve/CVE-2025-30474.html
* https://bugzilla.suse.com/show_bug.cgi?id=1239973
* https://bugzilla.suse.com/show_bug.cgi?id=1239974
Get the latest Linux and open source security news straight to your inbox.