Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. org.apache.ivy/ivy
  4. ›
  5. CVE-2022-37865

CVE-2022-37865: Apache Ivy does not verify target path when extracting the archive

November 7, 2022 (updated May 2, 2025)

With Apache Ivy 2.4.0 an optional packaging attribute has been introduced that allows artifacts to be unpacked on the fly if they used pack200 or zip packaging.

For artifacts using the “zip”, “jar” or “war” packaging Ivy prior to version 2.5.1 doesn’t verify the target path when extracting the archive. An archive containing absolute paths or paths that try to traverse “upwards” using “..” sequences can then write files to any location on the local fie system that the user executing Ivy has write access to.

Ivy users of version 2.4.0 to 2.5.0 should upgrade to Ivy version 2.5.1.

References

  • github.com/advisories/GHSA-94rr-4jr5-9h2p
  • lists.apache.org/thread/gqvvv7qsm2dfjg6xzsw1s2h08tbr0sdy
  • lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YDIFDL5WSBEKBUVKTABUFDDD25SBNJLS
  • lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YDIFDL5WSBEKBUVKTABUFDDD25SBNJLS
  • nvd.nist.gov/vuln/detail/CVE-2022-37865

Code Behaviors & Features

Detect and mitigate CVE-2022-37865 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 2.4.0 before 2.5.1

Fixed versions

  • 2.5.1

Solution

Upgrade to version 2.5.1 or above.

Impact 9.1 CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Source file

maven/org.apache.ivy/ivy/CVE-2022-37865.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:15:11 +0000.