CVE-2019-0191MEDIUMCVSS 6.5vApache Karaf version prior to 4.2.32019-03-21
CVE-2019-0191 [MEDIUM] CWE-22 CVE-2019-0191: Apache Karaf kar deployer reads .kar archives and extracts the paths from the "repository/" and "res
Apache Karaf kar deployer reads .kar archives and extracts the paths from the "repository/" and "resources/" entries in the zip file. It then writes out the content of these paths to the Karaf repo and resources directories. However, it doesn't do any validation on the paths in the zip file. This means that a malicious user could craft a .kar file with
cvelistv5nvd