Back

HIGH

karaf: SSH RBAC security enforcement

Published Sep 18, 2018

Description

In Apache Karaf prior to 4.2.0 release, if the sshd service in Karaf is left on so an administrator can manage the running instance, any user with rights to the Karaf console can pivot and read/write any file on the file system to which the Karaf process user has access. This can be locked down a bit by using chroot to change the root directory to protect files outside of the Karaf install directory; it can be further locked down by defining a security manager policy that limits file system access to those directories beneath the Karaf home that are necessary for the system to run. However, this still allows anyone with ssh access to the Karaf process to read and write a large number of files as the Karaf process user.

Affected products

Remediation

Red Hat statement

Open Daylight: The SSH console is enabled by default, with default credentials, and allows arbitrary file read and write, in addition to arbitrary command execution, in addition to regular Open Daylight Karaf functions.

Metrics

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Sep 18, 2018
Updated Sep 17, 2024
Reserved Jun 5, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Sep 18, 2018
GHSA-9448-C9WQ-JG9V