PT-2019-11183 · Apache · Apache Karaf

Colm O Heigeartaigh

·

Published

2019-03-20

·

Updated

2019-05-06

·

CVE-2019-0191

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions: Apache Karaf versions prior to 4.2.3
Description: The issue arises from the Apache Karaf kar deployer's failure to validate paths in .kar archives, allowing a malicious user to craft a .kar file with ".." directory names and write arbitrary content to the filesystem, known as the "Zip-slip" vulnerability. The impact of this issue is mitigated if the Karaf process user has limited permission on the filesystem.
Recommendations: For versions prior to 4.2.3, update to version 4.2.3 or later to resolve the issue. As a temporary workaround, consider restricting the permissions of the Karaf process user on the filesystem to minimize the risk of exploitation.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-0191
GHSA-869J-5855-HJPM

Affected Products

Apache Karaf