Known vulnerabilities in Apache Ivy
Vendor:
Apache Foundation
Software:
Apache Ivy
Software CPE:
cpe:2.3:a:apache_foundation:ivy:*:*:*:*:*:*:*:*
Website:
https://www.apache.org
Total vulnerabilities:
2
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
Vulnerabilities (2)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU79749 - Improper Restriction of XML External Entity Reference ('XXE') CVE-2022-46751 |
CWE-611 | High | 2.5.2 | 21.08.2023 |
SB2023082105 SB2023090730 SB2023101825 and 18 more |
||
| #VU75501 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2022-37866 |
CWE-22 | Medium | 2.5.1 | 26.04.2023 |
SB2023042603 SB2023050803 SB2023051504 and 7 more |