Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:37832
HistoryNov 08, 2022 - 3:35 a.m.

Arbitrary File Write

2022-11-0803:35:02
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
15
arbitrary file write
software
zippacking
vulnerability
absolute paths

0.001 Low

EPSS

Percentile

47.8%

apache ivy is vulnerable to arbitrary file write. The vulnerability exists due to the unpack function in ZipPacking.java not properly verifying the target path when extracting an artifact archive, allowing an attacker to write files to any location on the file system through the absolute paths or paths that try to traverse upwards using ... sequences.