Fedora 43 : apache-ivy (2026-d0535bed52)

medium Nessus Plugin ID 341826

Synopsis

The remote Fedora host is missing one or more security updates.

Description

The remote Fedora 43 host has a package installed that is affected by a vulnerability as referenced in the FEDORA-2026-d0535bed52 advisory.


IMPROVEMENT: ivy:retrieve and the 'post resolve tasks' now support the override child element. (IVY-1664)

IMPROVEMENT: ivy:makepom will now add override elements of the ivy.xml to the dependencyManagement section of the generated pom. (IVY-1663) (Thanks to Eric Milles)

IMPROVEMENT: ivy:deliver and ivy:publish now writes inherited dependencies first to preserve resolve order (IVY-1656) (Thanks to Eric Milles)

IMPROVEMENT: ModuleRevisionId.encodeToString now returns a deterministic string that doesnt rely on a implmentation of HashMap (Thanks to Arnout Engelen)

FIX: improved Maven dependencyManagement matching for dependencies with a non-default type or classifier (IVY-1654) (Thanks to Mark Kittisopikul)

FIX: the ivy:retrieve task failed when the retrieve pattern contained some text in parentheses before the first token, for instance: /jobs/lib (JDK 17)/[artifact].[ext] (IVY-1660)

FIX: when the ivy:deliver task is configured to replace dynamic revisions, it now replaces these revisions to the resolved revision before any conflict resolution was done, which was the original behavior before Ivy 2.3.0. This way, the delivered ivy.xml can be used to have reproducible dependency resolution, especially when multiple configurations are used. It also fixes issues where the dynamic revisions were replaced by versions from other configurations. (IVY-1485, IVY-1661)

FIX: the ivy:deliver task didnt replace dynamic revision from inherited dependencies. (IVY-1410) (Thanks to Eric Milles)

FIX: the ivy:install task didnt take the from resolver into account when resolving Maven parent modules or source/javadoc artifacts. (Thanks to Colin Chambers)

FIX: the ivy:checkdepsupdate task could suggest a lesser version as update. (IVY-1665) (Thanks to Eric Milles)

FIX: the ivy:makepom task no longer adds a dependency to the <dependencyManagement> section. (IVY-1667) (Thanks to Eric Milles)

FIX: the ivy:deliver task didnt include XML namespaces from a parent ivy module when merging the descriptors. (IVY-1658) (Thanks to Eric Milles)

FIX: the ivy:checkdepsupdate task no longer shows evicted versions. (IVY-1662) (Thanks to Eric Milles)



Tenable has extracted the preceding description block directly from the Fedora security advisory.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Update the affected apache-ivy package.

See Also

https://bodhi.fedoraproject.org/updates/FEDORA-2026-d0535bed52

Plugin Details

Severity: Medium

ID: 341826

File Name: fedora_2026-d0535bed52.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 8/31/2026

Updated: 8/31/2026

Supported Sensors: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: Low

Score: 2.1

Percentile: 7.92

CVSS v2

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.1

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:N

CVSS Score Source: CVE-2026-26032

CVSS v3

Risk Factor: Medium

Base Score: 5.4

Temporal Score: 4.7

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:fedoraproject:fedora:43, p-cpe:/a:fedoraproject:fedora:apache-ivy

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 8/21/2026

Vulnerability Publication Date: 7/15/2026

Reference Information

CVE: CVE-2026-26032