Apache Ivy: XML External Entity vulnerability in Apache Ivy
Published Aug 21, 2023
8.8
HIGHCVSS 4.0
EPSS 2.00%
Description
Improper Restriction of XML External Entity Reference, XML Injection (aka Blind XPath Injection) vulnerability in Apache Software Foundation Apache Ivy.This issue affects any version of Apache Ivy prior to 2.5.2.
When Apache Ivy prior to 2.5.2 parses XML files - either its own configuration, Ivy files or Apache Maven POMs - it will allow downloading external document type definitions and expand any entity references contained therein when used.
This can be used to exfiltrate data, access resources only the machine running Ivy has access to or disturb the execution of Ivy in different ways.
Starting with Ivy 2.5.2 DTD processing is disabled by default except when parsing Maven POMs where the default is to allow DTD processing but only to include a DTD snippet shipping with Ivy that is needed to deal with existing Maven POMs that are not valid XML files but are nevertheless accepted by Maven. Access can be be made more lenient via newly introduced system properties where needed.
Users of Ivy prior to version 2.5.2 can use Java system properties to restrict processing of external DTDs, see the section about "JAXP Properties for External Access restrictions" inside Oracle's "Java API for XML Processing (JAXP) Security Guide".
Affected products
-
- Version 1.0.0StatusaffectedConstraints<=2.5.1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Apache Software Foundation | Apache Ivy | unaffected |
|
-
- Version 1.0.0StatusaffectedConstraints<=2.5.1
- Version
MTA-6.2-RHEL-8
mta/mta-rhel8-operator:6.2.2-3
Fixed · RHSA-2024:1027
MTA-6.2-RHEL-9
mta/mta-hub-rhel9:6.2.2-2
Fixed · RHSA-2024:1027
MTA-6.2-RHEL-9
mta/mta-operator-bundle:6.2.2-5
Fixed · RHSA-2024:1027
MTA-6.2-RHEL-9
mta/mta-pathfinder-rhel9:6.2.2-2
Fixed · RHSA-2024:1027
MTA-6.2-RHEL-9
mta/mta-ui-rhel9:6.2.2-2
Fixed · RHSA-2024:1027
MTA-6.2-RHEL-9
mta/mta-windup-addon-rhel9:6.2.2-3
Fixed · RHSA-2024:1027
MTR 1.2.4
apache-ivy
Fixed · RHSA-2024:0720
RHINT Camel-Springboot 4.0.0
apache-ivy
Fixed · RHSA-2023:5441
Red Hat AMQ Streams 2.6.0
apache-ivy
Fixed · RHSA-2023:7678
A-MQ Clients 2
apache-ivy
Not affected
Red Hat Data Grid 8
apache-ivy
Not affected
Red Hat Enterprise Linux 7
apache-ivy
Out of support scope
Red Hat Enterprise Linux 8
apache-ivy
Not affected
Red Hat Fuse 7
apache-ivy
Will not fix
Red Hat Integration Camel K 1
apache-ivy
Will not fix
Red Hat JBoss Data Grid 7
apache-ivy
Not affected
Red Hat JBoss Enterprise Application Platform 6
apache-ivy
Not affected
Red Hat JBoss Enterprise Application Platform 7
apache-ivy
Not affected
Red Hat JBoss Enterprise Application Platform 8
apache-ivy
Not affected
Red Hat JBoss Enterprise Application Platform Expansion Pack
apache-ivy
Not affected
Red Hat OpenShift Application Runtimes
apache-ivy
Not affected
Red Hat Single Sign-On 7
apache-ivy
Not affected
Red Hat Software Collections
rh-maven36-apache-ivy
Will not fix
Red Hat build of Apache Camel for Spring Boot 3
apache-ivy
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| MTA-6.2-RHEL-8 | mta/mta-rhel8-operator:6.2.2-3 | Fixed | RHSA-2024:1027 |
| MTA-6.2-RHEL-9 | mta/mta-hub-rhel9:6.2.2-2 | Fixed | RHSA-2024:1027 |
| MTA-6.2-RHEL-9 | mta/mta-operator-bundle:6.2.2-5 | Fixed | RHSA-2024:1027 |
| MTA-6.2-RHEL-9 | mta/mta-pathfinder-rhel9:6.2.2-2 | Fixed | RHSA-2024:1027 |
| MTA-6.2-RHEL-9 | mta/mta-ui-rhel9:6.2.2-2 | Fixed | RHSA-2024:1027 |
| MTA-6.2-RHEL-9 | mta/mta-windup-addon-rhel9:6.2.2-3 | Fixed | RHSA-2024:1027 |
| MTR 1.2.4 | apache-ivy | Fixed | RHSA-2024:0720 |
| RHINT Camel-Springboot 4.0.0 | apache-ivy | Fixed | RHSA-2023:5441 |
| Red Hat AMQ Streams 2.6.0 | apache-ivy | Fixed | RHSA-2023:7678 |
| A-MQ Clients 2 | apache-ivy | Not affected | n/a |
| Red Hat Data Grid 8 | apache-ivy | Not affected | n/a |
| Red Hat Enterprise Linux 7 | apache-ivy | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | apache-ivy | Not affected | n/a |
| Red Hat Fuse 7 | apache-ivy | Will not fix | n/a |
| Red Hat Integration Camel K 1 | apache-ivy | Will not fix | n/a |
| Red Hat JBoss Data Grid 7 | apache-ivy | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | apache-ivy | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | apache-ivy | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | apache-ivy | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | apache-ivy | Not affected | n/a |
| Red Hat OpenShift Application Runtimes | apache-ivy | Not affected | n/a |
| Red Hat Single Sign-On 7 | apache-ivy | Not affected | n/a |
| Red Hat Software Collections | rh-maven36-apache-ivy | Will not fix | n/a |
| Red Hat build of Apache Camel for Spring Boot 3 | apache-ivy | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Sep 27, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2023–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (10 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 2.00% (0.01999) | 79.99th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.84% (0.01840) | 76.13th | v5 (v2026.06.15) |
| Nov 21, 2025 | 0.12% (0.00124) | 32.36th | v4 (v2025.03.14) |
| Nov 18, 2025 | 8.72% (0.08724) | 91.63th | v4 (v2025.03.14) |
| Mar 17, 2025 | 0.07% (0.00068) | 18.27th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.15% (0.00153) | 52.94th | v3 (v2023.03.01) |
| Feb 26, 2024 | 0.13% (0.00127) | 46.26th | v3 (v2023.03.01) |
| Dec 6, 2023 | 0.12% (0.00120) | 45.85th | v3 (v2023.03.01) |
| Sep 1, 2023 | 0.15% (0.00151) | 50.66th | v3 (v2023.03.01) |
| Aug 21, 2023 | 0.05% (0.00052) | 18.00th | v3 (v2023.03.01) |
References (11)
- http://www.openwall.com/lists/oss-security/2023/09/06/9
- https://access.redhat.com/security/cve/CVE-2022-46751 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2233112 Issue Tracking
- https://docs.oracle.com/en/java/javase/13/security/java-api-xml-processing-jaxp-security-guide.html#GUID-94ABC0EE-9DC8-44F0-84AD-47ADD5340477 mitigationThird Party Advisory
- https://gitbox.apache.org/repos/asf?p=ant-ivy.git;a=commit;h=2be17bc18b0e1d4123007d579e43ba1a4b6fab3d patchVendor Advisory
- https://github.com/advisories/GHSA-2jc4-r94c-rp7h Advisory
- https://github.com/apache/ant-ivy/commit/2be17bc18b0e1d4123007d579e43ba1a4b6fab3d
- https://lists.apache.org/thread/1dj60hg5nr36kjr4p1100dwjrqookps8 vendor-advisoryMailing ListVendor Advisory
- https://lists.apache.org/thread/9gcz4xrsn8c7o9gb377xfzvkb8jltffr release-notesMailing ListVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-46751
- https://www.cve.org/CVERecord?id=CVE-2022-46751
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2023/09/06/9 | ||
| https://access.redhat.com/security/cve/CVE-2022-46751 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2233112 | Issue Tracking | |
| https://docs.oracle.com/en/java/javase/13/security/java-api-xml-processing-jaxp-security-guide.html#GUID-94ABC0EE-9DC8-44F0-84AD-47ADD5340477 | mitigationThird Party Advisory | |
| https://gitbox.apache.org/repos/asf?p=ant-ivy.git;a=commit;h=2be17bc18b0e1d4123007d579e43ba1a4b6fab3d | patchVendor Advisory | |
| https://github.com/advisories/GHSA-2jc4-r94c-rp7h | Advisory | |
| https://github.com/apache/ant-ivy/commit/2be17bc18b0e1d4123007d579e43ba1a4b6fab3d | ||
| https://lists.apache.org/thread/1dj60hg5nr36kjr4p1100dwjrqookps8 | vendor-advisoryMailing ListVendor Advisory | |
| https://lists.apache.org/thread/9gcz4xrsn8c7o9gb377xfzvkb8jltffr | release-notesMailing ListVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-46751 | ||
| https://www.cve.org/CVERecord?id=CVE-2022-46751 |
Change history (0)
No recorded changes yet.