CVE-2019-0191
published 2019-03-21CVE-2019-0191: Apache Karaf kar deployer reads .kar archives and extracts the paths from the "repository/" and "resources/" entries in the zip file. It then writes out the…
PriorityP341medium6.5CVSS 3.0
AVNACLPRLUINSUCNIHAN
EPSS
4.86%
91.0th percentile
Apache Karaf kar deployer reads .kar archives and extracts the paths from the "repository/" and "resources/" entries in the zip file. It then writes out the content of these paths to the Karaf repo and resources directories. However, it doesn't do any validation on the paths in the zip file. This means that a malicious user could craft a .kar file with ".." directory names and break out of the directories to write arbitrary content to the filesystem. This is the "Zip-slip" vulnerability - https://snyk.io/research/zip-slip-vulnerability. This vulnerability is low if the Karaf process user has limited permission on the filesystem. Any Apache Karaf releases prior 4.2.3 is impacted.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | apache_karaf | — | — |
| apache | karaf | < 4.2.3 | 4.2.3 |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
karaf: Zip-slip vulnerability via kar file
vendor_redhat·2019-03-07·CVSS 6.5
CVE-2019-0191 [MEDIUM] CWE-20 karaf: Zip-slip vulnerability via kar file
karaf: Zip-slip vulnerability via kar file
Apache Karaf kar deployer reads .kar archives and extracts the paths from the "repository/" and "resources/" entries in the zip file. It then writes out the content of these paths to the Karaf repo and resources directories. However, it doesn't do any validation on the paths in the zip file. This means that a malicious user could craft a .kar file with ".." directory names and break out of the directories to write arbitrary content to the filesystem. This is the "Zip-slip" vulnerability - https://snyk.io/research/zip-slip-vulnerability. This vulnerability is low if the Karaf process user has limited permission on the filesystem. Any Apache Karaf releases prior 4.2.3 is impacted.
Statement: All versions of Red Hat OpenStack Platform's OpenDayligh
OSV
Moderate severity vulnerability that affects org.apache.karaf:apache-karaf and org.apache.karaf:karaf
osv·2019-03-25
CVE-2019-0191 [MEDIUM] Moderate severity vulnerability that affects org.apache.karaf:apache-karaf and org.apache.karaf:karaf
Moderate severity vulnerability that affects org.apache.karaf:apache-karaf and org.apache.karaf:karaf
Apache Karaf kar deployer reads .kar archives and extracts the paths from the "repository/" and "resources/" entries in the zip file. It then writes out the content of these paths to the Karaf repo and resources directories. However, it doesn't do any validation on the paths in the zip file. This means that a malicious user could craft a .kar file with ".." directory names and break out of the directories to write arbitrary content to the filesystem. This is the "Zip-slip" vulnerability - https://snyk.io/research/zip-slip-vulnerability. This vulnerability is low if the Karaf process user has limited permission on the filesystem. Any Apache Karaf releases prior 4.2.3 is impacted.
GHSA
Moderate severity vulnerability that affects org.apache.karaf:apache-karaf and org.apache.karaf:karaf
ghsa·2019-03-25
CVE-2019-0191 [MEDIUM] CWE-22 Moderate severity vulnerability that affects org.apache.karaf:apache-karaf and org.apache.karaf:karaf
Moderate severity vulnerability that affects org.apache.karaf:apache-karaf and org.apache.karaf:karaf
Apache Karaf kar deployer reads .kar archives and extracts the paths from the "repository/" and "resources/" entries in the zip file. It then writes out the content of these paths to the Karaf repo and resources directories. However, it doesn't do any validation on the paths in the zip file. This means that a malicious user could craft a .kar file with ".." directory names and break out of the directories to write arbitrary content to the filesystem. This is the "Zip-slip" vulnerability - https://snyk.io/research/zip-slip-vulnerability. This vulnerability is low if the Karaf process user has limited permission on the filesystem. Any Apache Karaf releases prior 4.2.3 is impacted.
No detection rules found.
No public exploits indexed.
CTF
20190323-0ctf_tctf2019quals / README
ctf_writeups·2019
20190323-0ctf_tctf2019quals / README
# 0CTF/TCTF 2019 Quals
**It's recommended to read our responsive [web version](https://balsn.tw/ctf_writeup/20190323-0ctf_tctf2019quals/) of this writeup.**
- [0CTF/TCTF 2019 Quals](#0ctftctf-2019-quals)
- [Pwn](#pwn)
- [babyaegis](#babyaegis)
- [If on a winters night a traveler](#if-on-a-winters-night-a-traveler)
- [zerotask](#zerotask)
- [plang](#plang)
- [Vulnerability](#vulnerability)
- [Leak](#leak)
- [exploit](#exploit)
- [Web](#web)
- [Ghost Pepper](#ghost-pepper)
- [Failed Attempts](#failed-attempts)
- [Wallbreaker Easy](#wallbreaker-easy)
- [Solution 1: Bypass open_basedir](#solution-1-bypass-open_basedir)
- [Solution 2: Bypass disable_function with LD_PRELOAD](#solution-2-bypass-disable_function-with-ld_preload)
- [Failed Attempts](#failed-attempts-1)
- [Reverse](#reverse)
- [
Bugzilla
CVE-2019-0191 karaf: Zip-slip vulnerability via kar file
bugzilla·2019-04-04·CVSS 6.5
CVE-2019-0191 [MEDIUM] CVE-2019-0191 karaf: Zip-slip vulnerability via kar file
CVE-2019-0191 karaf: Zip-slip vulnerability via kar file
Apache Karaf kar deployer reads .kar archives and extracts the paths from the "repository/" and "resources/" entries in the zip file. It then writes out the content of these paths to the Karaf repo and resources directories. However, it doesn't do any validation on the paths in the zip file. This means that a malicious user could craft a .kar file with ".." directory names and break out of the directories to write arbitrary content to the filesystem. This is the "Zip-slip" vulnerability - https://snyk.io/research/zip-slip-vulnerability. This vulnerability is low if the Karaf process user has limited permission on the filesystem. Any Apache Karaf releases prior 4.2.3 is impacted.
References:
https://lists.apache.org/thread.html/685
http://www.securityfocus.com/bid/107462https://lists.apache.org/thread.html/6856aa7ed7dd805eaf65d0e5e95027dda3b2307aacd1ab4a838c5cd1%40%3Cuser.karaf.apache.org%3Ehttps://lists.apache.org/thread.html/cef9a2d4b547625e5214684283ac5c59c9d9740e092e777dc3f85070%40%3Ccommits.karaf.apache.org%3Ehttp://www.securityfocus.com/bid/107462https://lists.apache.org/thread.html/6856aa7ed7dd805eaf65d0e5e95027dda3b2307aacd1ab4a838c5cd1%40%3Cuser.karaf.apache.org%3Ehttps://lists.apache.org/thread.html/cef9a2d4b547625e5214684283ac5c59c9d9740e092e777dc3f85070%40%3Ccommits.karaf.apache.org%3E
2019-03-21
Published