PT-2026-4647 · Apache · Apache Karaf+1

R00T4Dm

·

Publicado

2026-01-25

·

Atualizado

2026-03-03

·

CVE-2026-24656

CVSS v3.1

3.7

Baixa

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Apache Karaf Decanter versions prior to 2.12.0
Description The Decanter log socket collector in Apache Karaf has a deserialization issue. The collector operates on port 4560 without authentication. If the allowed classes property is exposed, its configuration can be bypassed, leading to potential denial-of-service (DoS) conditions due to untrusted data deserialization. The Decanter log socket collector is not installed by default, meaning users who have not installed it are not affected.
Recommendations Upgrade to version 2.12.0 or later.

Correção

DoS

Deserialization of Untrusted Data

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-24656
GHSA-JMW5-58C7-587H

Produtos afetados

Apache Karaf
Decanter