Apache

Karaf

19 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.31%
  • Veröffentlicht 29.09.2026 09:17:10
  • Zuletzt bearbeitet 07.10.2026 20:07:16

Apache Karaf exposes a JMX MBeanServer guarded by KarafMBeanServerGuard, which enforces role-based access control (RBAC) on MBean operations invoked over the remote JMX connector (RMI registry/server, enabled by default on ports 1099 and 44444). The ...

  • EPSS 0.16%
  • Veröffentlicht 29.09.2026 09:17:10
  • Zuletzt bearbeitet 07.10.2026 20:11:43

Apache Karaf's shell/SSH command security is enforced by per-scope ACL configuration files (etc/org.apache.karaf.command.acl.<scope>.cfg). SecuredSessionFactoryImpl.checkSecurity() resolves the roles required for an invocation and, when no ACL rule m...

  • EPSS 0.19%
  • Veröffentlicht 29.09.2026 09:17:10
  • Zuletzt bearbeitet 07.10.2026 20:14:54

The jdbc shell command scope shipped no org.apache.karaf.command.acl.jdbc.cfg. Karaf's command guard (SecuredSessionFactoryImpl) treats a command with no matching ACL rule as allowed, so any authenticated shell session (including one holding only the...

  • EPSS 0.17%
  • Veröffentlicht 29.09.2026 09:17:09
  • Zuletzt bearbeitet 07.10.2026 20:16:25

org.apache.karaf.config.core.impl.ConfigRepositoryImpl#update(pid, properties), which backs the "config" MBean and the config:* shell commands, derives the file it writes a configuration to from caller-supplied input without checking that the result ...

  • EPSS 0.4%
  • Veröffentlicht 28.09.2026 10:44:32
  • Zuletzt bearbeitet 29.09.2026 22:19:03

Apache Karaf's instance-management service (InstanceServiceImpl) builds the command line used to launch a child Karaf JVM by string concatenation, then executes it through /bin/sh (Unix) or cscript (Windows). The caller-supplied javaOpts value is spl...

  • EPSS 0.25%
  • Veröffentlicht 28.09.2026 09:34:33
  • Zuletzt bearbeitet 30.09.2026 20:17:36

LDAPCache and LDAPBackingEngine build LDAP search filters for user lookup and role lookup by textually substituting the placeholders %u, %dn, and %fqdn (drawn from the login name, the resolved user DN, and its fully qualified namespace form) into adm...

  • EPSS 0.4%
  • Veröffentlicht 17.09.2026 18:38:29
  • Zuletzt bearbeitet 18.09.2026 17:48:19

Apache Karaf's XmlUtils cached XML parser/transformer factories in static ThreadLocal fields on long-lived container threads. Because a ThreadLocal value outlives the OSGi bundle that created it, repeated bundle or feature install, update, or refresh...

  • EPSS 2.4%
  • Veröffentlicht 21.12.2022 16:15:08
  • Zuletzt bearbeitet 15.04.2025 18:15:44

This vulnerable is about a potential code injection when an attacker has control of the target LDAP server using in the JDBC JNDI URL. The function jaas.modules.src.main.java.porg.apache.karaf.jass.modules.jdbc.JDBCUtils#doCreateDatasource use Initi...

  • EPSS 2.83%
  • Veröffentlicht 26.01.2022 11:15:09
  • Zuletzt bearbeitet 21.11.2024 06:47:38

Apache Karaf obr:* commands and run goal on the karaf-maven-plugin have partial path traversal which allows to break out of expected folder. The risk is low as obr:* commands are not very used and the entry is set by user. This has been fixed in revi...

  • EPSS 2.03%
  • Veröffentlicht 26.01.2022 11:15:08
  • Zuletzt bearbeitet 21.11.2024 06:26:43

Apache Karaf allows monitoring of applications and the Java runtime by using the Java Management Extensions (JMX). JMX is a Java RMI based technology that relies on Java serialized objects for client server communication. Whereas the default JMX impl...