Логотип exploitDog
bind: "CVE-2022-37865"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2022-37865"

Количество 5

Количество 5

redhat логотип

CVE-2022-37865

больше 2 лет назад

With Apache Ivy 2.4.0 an optional packaging attribute has been introduced that allows artifacts to be unpacked on the fly if they used pack200 or zip packaging. For artifacts using the "zip", "jar" or "war" packaging Ivy prior to 2.5.1 doesn't verify the target path when extracting the archive. An archive containing absolute paths or paths that try to traverse "upwards" using ".." sequences can then write files to any location on the local fie system that the user executing Ivy has write access to. Ivy users of version 2.4.0 to 2.5.0 should upgrade to Ivy 2.5.1.

CVSS3: 9.1
EPSS: Низкий
nvd логотип

CVE-2022-37865

больше 2 лет назад

With Apache Ivy 2.4.0 an optional packaging attribute has been introduced that allows artifacts to be unpacked on the fly if they used pack200 or zip packaging. For artifacts using the "zip", "jar" or "war" packaging Ivy prior to 2.5.1 doesn't verify the target path when extracting the archive. An archive containing absolute paths or paths that try to traverse "upwards" using ".." sequences can then write files to any location on the local fie system that the user executing Ivy has write access to. Ivy users of version 2.4.0 to 2.5.0 should upgrade to Ivy 2.5.1.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-94rr-4jr5-9h2p

больше 2 лет назад

Apache Ivy does not verify target path when extracting the archive

CVSS3: 9.1
EPSS: Низкий
fstec логотип

BDU:2024-02278

больше 2 лет назад

Уявимость пакетного менеджера Apache Ivy, связанная с неверным ограниченим имени пути к каталогу с ограниченным доступом, позволяющая нарушителю записать произвольные файлы в файловую систему

CVSS3: 9.1
EPSS: Низкий
redos логотип

ROS-20241203-20

7 месяцев назад

Множественные уязвимости apache-ivy

CVSS3: 9.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2022-37865

With Apache Ivy 2.4.0 an optional packaging attribute has been introduced that allows artifacts to be unpacked on the fly if they used pack200 or zip packaging. For artifacts using the "zip", "jar" or "war" packaging Ivy prior to 2.5.1 doesn't verify the target path when extracting the archive. An archive containing absolute paths or paths that try to traverse "upwards" using ".." sequences can then write files to any location on the local fie system that the user executing Ivy has write access to. Ivy users of version 2.4.0 to 2.5.0 should upgrade to Ivy 2.5.1.

CVSS3: 9.1
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2022-37865

With Apache Ivy 2.4.0 an optional packaging attribute has been introduced that allows artifacts to be unpacked on the fly if they used pack200 or zip packaging. For artifacts using the "zip", "jar" or "war" packaging Ivy prior to 2.5.1 doesn't verify the target path when extracting the archive. An archive containing absolute paths or paths that try to traverse "upwards" using ".." sequences can then write files to any location on the local fie system that the user executing Ivy has write access to. Ivy users of version 2.4.0 to 2.5.0 should upgrade to Ivy 2.5.1.

CVSS3: 9.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-94rr-4jr5-9h2p

Apache Ivy does not verify target path when extracting the archive

CVSS3: 9.1
0%
Низкий
больше 2 лет назад
fstec логотип
BDU:2024-02278

Уявимость пакетного менеджера Apache Ivy, связанная с неверным ограниченим имени пути к каталогу с ограниченным доступом, позволяющая нарушителю записать произвольные файлы в файловую систему

CVSS3: 9.1
0%
Низкий
больше 2 лет назад
redos логотип
ROS-20241203-20

Множественные уязвимости apache-ivy

CVSS3: 9.1
7 месяцев назад

Уязвимостей на страницу