PT-2017-5779 · Apache · Apache Karaf

Publicado

2017-11-15

·

Atualizado

2022-05-14

·

CVE-2014-0219

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Apache Karaf versions prior to 4.0.10
Description: The issue allows local users to cause a denial of service by sending a shutdown command to all listening high ports, as a shutdown port is enabled on the loopback interface.
Recommendations: For versions prior to 4.0.10, update to version 4.0.10 or later to resolve the issue. As a temporary workaround, consider restricting access to the shutdown port to minimize the risk of exploitation.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-0219
GHSA-M6G3-XQ5Q-4HG9

Produtos afetados

Apache Karaf