Apache / Karaf
12 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2022-40145 | Apache Karaf: JDBC JAAS LDAP injection | CRITICAL | 9.8 | Dec 21, 2022 |
| CVE-2022-22932 | Path traversal flaws | MEDIUM | 5.4 | Jan 26, 2022 |
| CVE-2021-41766 | Insecure Java Deserialization in Apache Karaf | HIGH | 8.1 | Jan 26, 2022 |
| CVE-2020-28052 | bouncycastle: password bypass in OpenBSDBCrypt.checkPassword utility possible | HIGH | 8.1 | Dec 18, 2020 |
| CVE-2020-11980 | karaf: A remote client could create MBeans from arbitrary URLs | HIGH | 8.8 | Jun 12, 2020 |
| CVE-2019-0226 | Apache Karaf Config service provides a install method (via service or MBean) that could be used to travel in any directory and overwrite existing file. The vul… | MEDIUM | 4.9 | May 9, 2019 |
| CVE-2019-0191 | karaf: Zip-slip vulnerability via kar file | MEDIUM | 6.5 | Mar 20, 2019 |
| CVE-2018-11788 | karaf: XML external entity processing | CRITICAL | 9.8 | Jan 7, 2019 |
| CVE-2018-11787 | karaf: Authentication bypass access to Gogo shell in the webconsole | CRITICAL | 9.4 | Sep 18, 2018 |
| CVE-2018-11786 | karaf: SSH RBAC security enforcement | HIGH | 8.8 | Sep 18, 2018 |
| CVE-2016-8648 | Karaf JMX Console RCE during deserialization | HIGH | 7.2 | Aug 1, 2018 |
| CVE-2016-8750 | karaf: LDAP injection in LDAPLoginModule | HIGH | 7.5 | Feb 19, 2018 |
| CVE-2014-0219 | Karaf: denial of service via shutdown port | MEDIUM | 5.5 | Nov 15, 2017 |
Showing 1 to 12 of 12 CVEs