Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS05NHJyLTRqcjUtOWgycM4AAvuM

Apache Ivy does not verify target path when extracting the archive

With Apache Ivy 2.4.0 an optional packaging attribute has been introduced that allows artifacts to be unpacked on the fly if they used
pack200 or zip packaging.

For artifacts using the "zip", "jar" or "war" packaging Ivy prior to version 2.5.1 doesn't verify the target path when extracting the archive. An archive containing absolute paths or paths that try to traverse "upwards" using ".." sequences can then write files to any location on
the local fie system that the user executing Ivy has write access to.

Ivy users of version 2.4.0 to 2.5.0 should upgrade to Ivy version 2.5.1.

Permalink: https://github.com/advisories/GHSA-94rr-4jr5-9h2p
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS05NHJyLTRqcjUtOWgycM4AAvuM
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Critical
Classification: General
Published: about 2 years ago
Updated: over 1 year ago


CVSS Score: 9.1
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

EPSS Percentage: 0.00123
EPSS Percentile: 0.47641

Identifiers: GHSA-94rr-4jr5-9h2p, CVE-2022-37865
References: Blast Radius: 35.2

Affected Packages

maven:org.apache.ivy:ivy
Dependent packages: 293
Dependent repositories: 7,353
Downloads:
Affected Version Ranges: >= 2.4.0, < 2.5.1
Fixed in: 2.5.1
All affected versions: 2.4.0, 2.5.0
All unaffected versions: 2.0.0, 2.1.0, 2.2.0, 2.3.0, 2.5.1, 2.5.2