CVE-2022-37866 - CVE House
Back to Database
Status published Unknown CVE-2022-37866

Apache Ivy allows path traversal in the presence of a malicious repository

Vulnerability Description

When Apache Ivy downloads artifacts from a repository it stores them in the local file system based on a user-supplied "pattern" that may include placeholders for artifacts coordinates like the organisation, module or version. If said coordinates contain "../" sequences - which are valid characters for Ivy coordinates in general - it is possible the artifacts are stored outside of Ivy's local cache or repository or can overwrite different artifacts inside of the local cache. In order to exploit this vulnerability an attacker needs collaboration by the remote repository as Ivy will issue http requests containing ".." sequences and a "normal" repository will not interpret them as part of the artifact coordinates. Users of Apache Ivy 2.0.0 to 2.5.1 should upgrade to Ivy 2.5.1.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-37866

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • This issue was discovered by Kostya Kortchinsky of the Databricks Security Team.

Affected Vendor

Apache Software Foundation

View all reports →

Affected Software

Apache Ivy
Vulnerable Versions:
2.0.0, unspecified

Timeline

Official Publish: November 7th, 2022
Last Modified: May 1st, 2025
Added to House: July 21st, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)