cbcvebase.
CVE-2022-46751
published 2023-08-21

CVE-2022-46751: Improper Restriction of XML External Entity Reference, XML Injection (aka Blind XPath Injection) vulnerability in Apache Software Foundation Apache Ivy.This…

high8.2CVSS 3.1
AVNACLPRNUINSUCHINAL
Improper Restriction of XML External Entity Reference, XML Injection (aka Blind XPath Injection) vulnerability in Apache Software Foundation Apache Ivy.This issue affects any version of Apache Ivy prior to 2.5.2. When Apache Ivy prior to 2.5.2 parses XML files - either its own configuration, Ivy files or Apache Maven POMs - it will allow downloading external document type definitions and expand any entity references contained therein when used. This can be used to exfiltrate data, access resources only the machine running Ivy has access to or disturb the execution of Ivy in different ways. Starting with Ivy 2.5.2 DTD processing is disabled by default except when parsing Maven POMs where the default is to allow DTD processing but only to include a DTD snippet shipping with Ivy that is needed to deal with existing Maven POMs that are not valid XML files but are nevertheless accepted by Maven. Access can be be made more lenient via newly introduced system properties where needed. Users of Ivy prior to version 2.5.2 can use Java system properties to restrict processing of external DTDs, see the section about "JAXP Properties for External Access restrictions" inside Oracle's "Java API for XML Processing (JAXP) Security Guide".

Affected

24 ranges
VendorProductVersion rangeFixed in
apacheivy< 2.5.22.5.2
apache_software_foundationapache_ivy1.0.0 – 2.5.1
jenkinsassembla_auth_plugin
jenkinsauthorize_project_plugin
jenkinsaws_codecommit_trigger_plugin
jenkinsbitbucket_push_and_pull_request_plugin
jenkinsconfig_file_provider_plugin
jenkinsdeclarative_plugin
jenkinsdisabled_permissions_can_be_granted_by_ssh2_easy_plugin
jenkinsdisabled_permissions_granted_by_assembla_auth_plugin
jenkinsfrugal_testing_plugin
jenkinsgoogle_login_plugin
jenkinsgroovy_plugin
jenkinsivy_plugin
jenkinsivytrigger_plugin
jenkinsjob_configuration_history_plugin
jenkinsnon-constant_time_token_comparison_in_google_login_plugin
jenkinsopenid_connect_authentication_plugin
jenkinspipeline_maven_integration_plugin
jenkinsqualys_container_scanning_connector_plugin
jenkinsscript_security_plugin
jenkinsshared_library_version_override_plugin
jenkinsssh2_easy_plugin
jenkinstap_plugin