MEDIUM
Apache Karaf Config service provides a install method (via service or MBean) that could be used to travel in any directory and overwrite existing file
Published May 9, 2019
4.9
MEDIUMCVSS 3.0
EPSS 1.80%
Description
Apache Karaf Config service provides a install method (via service or MBean) that could be used to travel in any directory and overwrite existing file. The vulnerability is low if the Karaf process user has limited permission on the filesystem. Any Apache Karaf version before 4.2.5 is impacted. User should upgrade to Apache Karaf 4.2.5 or later.
Affected products
-
- Version prior to 4.2.5StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (8)
- https://github.com/advisories/GHSA-fjw4-39pg-vf4f Advisory
- https://github.com/apache/karaf/pull/805
- https://issues.apache.org/jira/browse/KARAF-6230
- https://lists.apache.org/thread.html/1baa6f1df0e95fb1cd679067117354af2ab4423277d9a0ff6e8bf790%40%3Cdev.karaf.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/1baa6f1df0e95fb1cd679067117354af2ab4423277d9a0ff6e8bf790@%3Cdev.karaf.apache.org%3E
- https://lists.apache.org/thread.html/r218c7e017af0a860ae21bf7ab77520fd2070c8f52db680eeec03a266%40%3Ccommits.karaf.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r218c7e017af0a860ae21bf7ab77520fd2070c8f52db680eeec03a266@%3Ccommits.karaf.apache.org%3E
- https://nvd.nist.gov/vuln/detail/CVE-2019-0226
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published May 9, 2019
Updated Aug 4, 2024
Reserved Nov 14, 2018
Link CVE-2019-0226
CISA Vulnrichment
GHSA-FJW4-39PG-VF4F Updated n/a