Fedora Account System
Red Hat Associate
Red Hat Customer
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process. The PackagerResolver of Apache Ivy is able to download online artifacts and to (re)package them in a format defined by a packager.xml file. This repackaging is done by an Ant script, which is stored in a subdirectory of the configured "buildRoot" directory. This subdirectory is calculated based on modules coordinates, like the organisation, name or version. If one of the coordinates contains "../" sequences - which are valid characters for Ivy coordinates in general- it is possible to break out of the configured "buildRoot" directory where other files can be overwritten. In order to exploit this vulnerability an attacker needs to have access to a packager repository and add or modify the coordinates in ivy.xml files to have such "../" sequences. Users of Apache Ivy 2.0.0 to 2.5.3 (inclusive) should upgrade to Ivy 2.6.0.
Ivy 2.6.0 is already in rawhide / F45, should we backport it to F44 and F43 too ? full changelog is here: https://ant.apache.org/ivy/history/2.6.0/release-notes.html
Yes, that would fix the vulnerability ;)
(In reply to Thibault Guittet from comment #2) > Yes, that would fix the vulnerability ;) I mean, let me check if the upgrade will cause some regressions or not... thanks.
FEDORA-2026-c02768c662 (apache-ivy-2.6.0-2.fc44) has been submitted as an update to Fedora 44. https://bodhi.fedoraproject.org/updates/FEDORA-2026-c02768c662
FEDORA-2026-d0535bed52 (apache-ivy-2.6.0-2.fc43) has been submitted as an update to Fedora 43. https://bodhi.fedoraproject.org/updates/FEDORA-2026-d0535bed52
FEDORA-2026-c02768c662 has been pushed to the Fedora 44 testing repository. Soon you'll be able to install the update with the following command: `sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-c02768c662` You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-c02768c662 See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.
FEDORA-2026-d0535bed52 has been pushed to the Fedora 43 testing repository. Soon you'll be able to install the update with the following command: `sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-d0535bed52` You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-d0535bed52 See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.
FEDORA-2026-d0535bed52 (apache-ivy-2.6.0-2.fc43) has been pushed to the Fedora 43 stable repository. If problem still persists, please make note of it in this bug report.
FEDORA-2026-c02768c662 (apache-ivy-2.6.0-2.fc44) has been pushed to the Fedora 44 stable repository. If problem still persists, please make note of it in this bug report.