First published: Mon Nov 07 2022(Updated: )
A flaw was found in Apache Ivy. With Apache Ivy 2.4.0, an optional packaging attribute was introduced that allows artifacts to be unpacked on the fly if pack200 or zip packaging was used. This issue could allow a malicious used to have unwanted access.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Ivy | >=2.4.0<2.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this flaw in Apache Ivy is CVE-2022-37865.
The severity of CVE-2022-37865 is critical.
The affected software is Apache Ivy version up to 2.5.1.
To fix this vulnerability, upgrade Apache Ivy to version 2.5.1 or later.
You can find more information about CVE-2022-37865 at the following references: [link1], [link2], [link3].