CVE-2022-37865
published 2022-11-07CVE-2022-37865: With Apache Ivy 2.4.0 an optional packaging attribute has been introduced that allows artifacts to be unpacked on the fly if they used pack200 or zip…
PriorityP351critical9.1CVSS 3.1
AVNACLPRNUINSUCNIHAH
EPSS
1.82%
76.3th percentile
With Apache Ivy 2.4.0 an optional packaging attribute has been introduced that allows artifacts to be unpacked on the fly if they used pack200 or zip packaging. For artifacts using the "zip", "jar" or "war" packaging Ivy prior to 2.5.1 doesn't verify the target path when extracting the archive. An archive containing absolute paths or paths that try to traverse "upwards" using ".." sequences can then write files to any location on the local fie system that the user executing Ivy has write access to. Ivy users of version 2.4.0 to 2.5.0 should upgrade to Ivy 2.5.1.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | ivy | >= 2.4.0 < 2.5.1 | 2.5.1 |
| apache_software_foundation | apache_ivy | >= 2.4.0 < unspecified | unspecified |
| apache_software_foundation | apache_ivy | unspecified – 2.5.0 | — |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
vendor_oracle9.1CRITICAL
vendor_redhat9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Apache Ivy does not verify target path when extracting the archive
ghsa·2022-11-07
CVE-2022-37865 [CRITICAL] CWE-22 Apache Ivy does not verify target path when extracting the archive
Apache Ivy does not verify target path when extracting the archive
With Apache Ivy 2.4.0 an optional packaging attribute has been introduced that allows artifacts to be unpacked on the fly if they used
pack200 or zip packaging.
For artifacts using the "zip", "jar" or "war" packaging Ivy prior to version 2.5.1 doesn't verify the target path when extracting the archive. An archive containing absolute paths or paths that try to traverse "upwards" using ".." sequences can then write files to any location on
the local fie system that the user executing Ivy has write access to.
Ivy users of version 2.4.0 to 2.5.0 should upgrade to Ivy version 2.5.1.
OSV
Apache Ivy does not verify target path when extracting the archive
osv·2022-11-07
CVE-2022-37865 [CRITICAL] Apache Ivy does not verify target path when extracting the archive
Apache Ivy does not verify target path when extracting the archive
With Apache Ivy 2.4.0 an optional packaging attribute has been introduced that allows artifacts to be unpacked on the fly if they used
pack200 or zip packaging.
For artifacts using the "zip", "jar" or "war" packaging Ivy prior to version 2.5.1 doesn't verify the target path when extracting the archive. An archive containing absolute paths or paths that try to traverse "upwards" using ".." sequences can then write files to any location on
the local fie system that the user executing Ivy has write access to.
Ivy users of version 2.4.0 to 2.5.0 should upgrade to Ivy version 2.5.1.
Oracle
Oracle Oracle MySQL Risk Matrix: Monitoring: General (Apache Ivy) — CVE-2022-37865
vendor_oracle·2023-07-15·CVSS 9.1
CVE-2022-37865 [CRITICAL] Oracle Oracle MySQL Risk Matrix: Monitoring: General (Apache Ivy) — CVE-2022-37865
Oracle Oracle MySQL Risk Matrix: Monitoring: General (Apache Ivy) vulnerability
CVE: CVE-2022-37865
CVSS: 9.1
Protocol: Multiple
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2023 (JUL 2023)
Oracle
Oracle Oracle Communications Risk Matrix: Installation (Apache Ivy) — CVE-2022-37865
vendor_oracle·2023-04-15·CVSS 9.1
CVE-2022-37865 [CRITICAL] Oracle Oracle Communications Risk Matrix: Installation (Apache Ivy) — CVE-2022-37865
Oracle Oracle Communications Risk Matrix: Installation (Apache Ivy) vulnerability
CVE: CVE-2022-37865
CVSS: 9.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Red Hat
apache-ivy: Directory Traversal
vendor_redhat·2022-11-07·CVSS 9.1
CVE-2022-37865 [CRITICAL] CWE-22 apache-ivy: Directory Traversal
apache-ivy: Directory Traversal
With Apache Ivy 2.4.0 an optional packaging attribute has been introduced that allows artifacts to be unpacked on the fly if they used pack200 or zip packaging. For artifacts using the "zip", "jar" or "war" packaging Ivy prior to 2.5.1 doesn't verify the target path when extracting the archive. An archive containing absolute paths or paths that try to traverse "upwards" using ".." sequences can then write files to any location on the local fie system that the user executing Ivy has write access to. Ivy users of version 2.4.0 to 2.5.0 should upgrade to Ivy 2.5.1.
A flaw was found in Apache Ivy. With Apache Ivy 2.4.0, an optional packaging attribute was introduced that allows artifacts to be unpacked on the fly if pack200 or zip packaging was used. This issu
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.apache.org/thread/gqvvv7qsm2dfjg6xzsw1s2h08tbr0sdyhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YDIFDL5WSBEKBUVKTABUFDDD25SBNJLS/https://lists.apache.org/thread/gqvvv7qsm2dfjg6xzsw1s2h08tbr0sdyhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YDIFDL5WSBEKBUVKTABUFDDD25SBNJLS/
2022-11-07
Published