First published: Fri Nov 04 2022(Updated: )
A flaw was found in Apache Ivy. This may allow an attacker to place artifacts inside and outside of Ivy's repository and overwrite artifacts that the user will use later.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Ivy | >=2.0.0<2.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this flaw is CVE-2022-37866.
CVE-2022-37866 has a severity score of 7.5 (High).
The affected software includes Apache Ivy version up to but not including 2.5.1.
An attacker can exploit CVE-2022-37866 by using '../' sequences in the artifact coordinates when downloading artifacts from a repository, which allows them to place artifacts inside and outside of the intended storage directory.
Yes, the fix for CVE-2022-37866 is to upgrade to Apache Ivy version 2.5.1.