CVE-2022-46751
published 2023-08-21CVE-2022-46751: Improper Restriction of XML External Entity Reference, XML Injection (aka Blind XPath Injection) vulnerability in Apache Software Foundation Apache Ivy.This…
PriorityP352high8.2CVSS 3.1
AVNACLPRNUINSUCHINAL
EPSS
1.85%
76.8th percentile
Improper Restriction of XML External Entity Reference, XML Injection (aka Blind XPath Injection) vulnerability in Apache Software Foundation Apache Ivy.This issue affects any version of Apache Ivy prior to 2.5.2.
When Apache Ivy prior to 2.5.2 parses XML files - either its own configuration, Ivy files or Apache Maven POMs - it will allow downloading external document type definitions and expand any entity references contained therein when used.
This can be used to exfiltrate data, access resources only the machine running Ivy has access to or disturb the execution of Ivy in different ways.
Starting with Ivy 2.5.2 DTD processing is disabled by default except when parsing Maven POMs where the default is to allow DTD processing but only to include a DTD snippet shipping with Ivy that is needed to deal with existing Maven POMs that are not valid XML files but are nevertheless accepted by Maven. Access can be be made more lenient via newly introduced system properties where needed.
Users of Ivy prior to version 2.5.2 can use Java system properties to restrict processing of external DTDs, see the section about "JAXP Properties for External Access restrictions" inside Oracle's "Java API for XML Processing (JAXP) Security Guide".
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | ivy | < 2.5.2 | 2.5.2 |
| apache_software_foundation | apache_ivy | 1.0.0 – 2.5.1 | — |
| jenkins | assembla_auth_plugin | — | — |
| jenkins | authorize_project_plugin | — | — |
| jenkins | aws_codecommit_trigger_plugin | — | — |
| jenkins | bitbucket_push_and_pull_request_plugin | — | — |
| jenkins | config_file_provider_plugin | — | — |
| jenkins | declarative_plugin | — | — |
| jenkins | disabled_permissions_can_be_granted_by_ssh2_easy_plugin | — | — |
| jenkins | disabled_permissions_granted_by_assembla_auth_plugin | — | — |
| jenkins | frugal_testing_plugin | — | — |
| jenkins | google_login_plugin | — | — |
| jenkins | groovy_plugin | — | — |
| jenkins | ivy_plugin | — | — |
| jenkins | ivytrigger_plugin | — | — |
| jenkins | job_configuration_history_plugin | — | — |
| jenkins | non-constant_time_token_comparison_in_google_login_plugin | — | — |
| jenkins | openid_connect_authentication_plugin | — | — |
| jenkins | pipeline_maven_integration_plugin | — | — |
| jenkins | qualys_container_scanning_connector_plugin | — | — |
| jenkins | script_security_plugin | — | — |
| jenkins | shared_library_version_override_plugin | — | — |
| jenkins | ssh2_easy_plugin | — | — |
| jenkins | tap_plugin | — | — |
CVSS provenance
nvdv3.18.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
vendor_oracle8.2HIGH
vendor_redhat8.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Apache Ivy External Entity Reference vulnerability
osv·2023-08-21
CVE-2022-46751 [HIGH] Apache Ivy External Entity Reference vulnerability
Apache Ivy External Entity Reference vulnerability
Improper Restriction of XML External Entity Reference, XML Injection (aka Blind XPath Injection) vulnerability in Apache Software Foundation Apache Ivy.This issue affects any version of Apache Ivy prior to 2.5.2.
When Apache Ivy prior to 2.5.2 parses XML files - either its own configuration, Ivy files or Apache Maven POMs - it will allow downloading external document type definitions and expand any entity references contained therein when used.
This can be used to exfiltrate data, access resources only the machine running Ivy has access to or disturb the execution of Ivy in different ways.
Starting with Ivy 2.5.2 DTD processing is disabled by default except when parsing Maven POMs where the default is to allow DTD processing but only t
GHSA
Apache Ivy External Entity Reference vulnerability
ghsa·2023-08-21
CVE-2022-46751 [HIGH] CWE-611 Apache Ivy External Entity Reference vulnerability
Apache Ivy External Entity Reference vulnerability
Improper Restriction of XML External Entity Reference, XML Injection (aka Blind XPath Injection) vulnerability in Apache Software Foundation Apache Ivy.This issue affects any version of Apache Ivy prior to 2.5.2.
When Apache Ivy prior to 2.5.2 parses XML files - either its own configuration, Ivy files or Apache Maven POMs - it will allow downloading external document type definitions and expand any entity references contained therein when used.
This can be used to exfiltrate data, access resources only the machine running Ivy has access to or disturb the execution of Ivy in different ways.
Starting with Ivy 2.5.2 DTD processing is disabled by default except when parsing Maven POMs where the default is to allow DTD processing but only t
Jenkins
Jenkins Security Advisory 2024-11-13
vendor_jenkins·2024-11-13·CVSS 4.3
CVE-2022-46751 [MEDIUM] Jenkins Security Advisory 2024-11-13
Title: Jenkins Security Advisory 2024-11-13
Jenkins Security Advisory 2024-11-13
Jenkins Security Home
For Administrators
Overview
Terminology
Vulnerabilities and Scoring
Security Advisories
Security Issues
Advisory Schedule
Vulnerabilities in Plugins
How We Fix Security Issues
For Reporters
Reporting Vulnerabilities
Jenkins CNA
For Maintainers
Overview
Vulnerabilities in Plugins
Jenkins Security Team
About
Contributions
This advisory announces vulnerabilities in the following Jenkins deliverables:
Authorize Project
Plugin
IvyTrigger
Plugin
OpenId Connect Authentication
Plugin
Pipeline: Declarative
Plugin
Pipeline: Groovy
Plugin
Script Security
Plugin
Shared L
Oracle
Oracle Oracle Communications Risk Matrix: ATS Framework (Apache Ivy) — CVE-2022-46751
vendor_oracle·2024-01-15·CVSS 8.2
CVE-2022-46751 [HIGH] Oracle Oracle Communications Risk Matrix: ATS Framework (Apache Ivy) — CVE-2022-46751
Oracle Oracle Communications Risk Matrix: ATS Framework (Apache Ivy) vulnerability
CVE: CVE-2022-46751
CVSS: 8.2
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2024 (JAN 2024)
Jenkins
Jenkins Security Advisory 2023-09-06
vendor_jenkins·2023-09-06·CVSS 4.3
CVE-2022-46751 [MEDIUM] Jenkins Security Advisory 2023-09-06
Title: Jenkins Security Advisory 2023-09-06
Jenkins Security Advisory 2023-09-06
Jenkins Security Home
For Administrators
Overview
Terminology
Vulnerabilities and Scoring
Security Advisories
Security Issues
Advisory Schedule
Vulnerabilities in Plugins
How We Fix Security Issues
For Reporters
Reporting Vulnerabilities
Jenkins CNA
For Maintainers
Overview
Vulnerabilities in Plugins
Jenkins Security Team
About
Contributions
This advisory announces vulnerabilities in the following Jenkins deliverables:
Assembla Auth
Plugin
AWS CodeCommit Trigger
Plugin
Bitbucket Push and Pull Request
Plugin
Frugal Testing
Plugin
Google Login
Plugin
Ivy
Plugin
Job Configuration His
Red Hat
apache-ivy: XML External Entity vulnerability
vendor_redhat·2023-08-20·CVSS 8.2
CVE-2022-46751 [HIGH] CWE-611 apache-ivy: XML External Entity vulnerability
apache-ivy: XML External Entity vulnerability
Improper Restriction of XML External Entity Reference, XML Injection (aka Blind XPath Injection) vulnerability in Apache Software Foundation Apache Ivy.This issue affects any version of Apache Ivy prior to 2.5.2.
When Apache Ivy prior to 2.5.2 parses XML files - either its own configuration, Ivy files or Apache Maven POMs - it will allow downloading external document type definitions and expand any entity references contained therein when used.
This can be used to exfiltrate data, access resources only the machine running Ivy has access to or disturb the execution of Ivy in different ways.
Starting with Ivy 2.5.2 DTD processing is disabled by default except when parsing Maven POMs where the default is to allow DTD processing but only to includ
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2023/09/06/9https://docs.oracle.com/en/java/javase/13/security/java-api-xml-processing-jaxp-security-guide.html#GUID-94ABC0EE-9DC8-44F0-84AD-47ADD5340477https://gitbox.apache.org/repos/asf?p=ant-ivy.git;a=commit;h=2be17bc18b0e1d4123007d579e43ba1a4b6fab3dhttps://lists.apache.org/thread/1dj60hg5nr36kjr4p1100dwjrqookps8https://lists.apache.org/thread/9gcz4xrsn8c7o9gb377xfzvkb8jltffrhttp://www.openwall.com/lists/oss-security/2023/09/06/9https://docs.oracle.com/en/java/javase/13/security/java-api-xml-processing-jaxp-security-guide.html#GUID-94ABC0EE-9DC8-44F0-84AD-47ADD5340477https://gitbox.apache.org/repos/asf?p=ant-ivy.git;a=commit;h=2be17bc18b0e1d4123007d579e43ba1a4b6fab3dhttps://lists.apache.org/thread/1dj60hg5nr36kjr4p1100dwjrqookps8https://lists.apache.org/thread/9gcz4xrsn8c7o9gb377xfzvkb8jltffr
2023-08-21
Published