Bug 2529299 (CVE-2026-78254)
| Summary: | CVE-2026-78254 org.apache.ant/ant: Apache Ant: Arbitrary file write via path traversal in ftp and scp tasks | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | aschwart, aszczucz, boliveir, csutherl, drichtar, dsoumis, ewittman, gbenhaim, gmalinko, janstey, jclere, jwon, mposolda, nipatil, niyer, pantinor, pdelbell, pjindal, plodge, rhel-process-autobot, rjohnson, rkubis, rmartinc, rmaucher, rstepani, ssilvert, sthorger, szappis, twaugh, vmuzikar, watson-tool-maintainers |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in Apache Ant. The ftp and scp tasks, used for downloading files, are vulnerable to a path traversal issue. A malicious remote server can exploit this by providing specially crafted relative paths, allowing it to write files outside the intended download directory. This could lead to an attacker overwriting arbitrary files on the system with the permissions of the user running Ant, potentially compromising the system's integrity.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2531705, 2531706, 2531709, 2531710, 2531711, 2531712, 2531713, 2531714, 2531715, 2531716, 2531707, 2531708 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-09-07 07:51:25 UTC
|