Apache Software Foundation Apache Karaf vulnerabilities
8 known vulnerabilities affecting apache_software_foundation/apache_karaf.
Total CVEs
8
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH3MEDIUM2LOW1
Vulnerabilities
Page 1 of 1
CVE-2026-24656LOWCVSS 3.7fixed in 2.12.02026-01-26
CVE-2026-24656 [LOW] CWE-502 CVE-2026-24656: Deserialization of Untrusted Data vulnerability in Apache Karaf Decanter.
The Decanter log socket
Deserialization of Untrusted Data vulnerability in Apache Karaf Decanter.
The Decanter log socket collector exposes the port 4560, without authentication. If the collector exposes allowed classes property, this configuration can be bypassed.
It means that the log socket collector is vulnerable to deserialization of untrusted data, eventually causing D
cvelistv5nvd
CVE-2022-40145CRITICALCVSS 9.8≥ 4.4.0, < 4.4.2fixed in 4.3.82022-12-21
CVE-2022-40145 [CRITICAL] CWE-20 CVE-2022-40145: This vulnerable is about a potential code injection when an attacker has control of the target LDAP
This vulnerable is about a potential code injection when an attacker has control of the target LDAP server using in the JDBC JNDI URL.
The function jaas.modules.src.main.java.porg.apache.karaf.jass.modules.jdbc.JDBCUtils#doCreateDatasource
use InitialContext.lookup(jndiName) without filtering.
An user can modify `options.put(JDBCUtils.DATASOURCE, "
cvelistv5nvd
CVE-2021-41766HIGHCVSS 8.1≥ Apache Karaf, < 4.3.62022-01-26
CVE-2021-41766 [HIGH] CWE-502 CVE-2021-41766: Apache Karaf allows monitoring of applications and the Java runtime by using the Java Management Ext
Apache Karaf allows monitoring of applications and the Java runtime by using the Java Management Extensions (JMX). JMX is a Java RMI based technology that relies on Java serialized objects for client server communication. Whereas the default JMX implementation is hardened against unauthenticated deserialization attacks, the implementation used by Apac
cvelistv5nvd
CVE-2022-22932MEDIUMCVSS 5.3≥ Apache Karaf, < 4.2.152022-01-26
CVE-2022-22932 [MEDIUM] CWE-22 CVE-2022-22932: Apache Karaf obr:* commands and run goal on the karaf-maven-plugin have partial path traversal which
Apache Karaf obr:* commands and run goal on the karaf-maven-plugin have partial path traversal which allows to break out of expected folder. The risk is low as obr:* commands are not very used and the entry is set by user. This has been fixed in revision: https://gitbox.apache.org/repos/asf?p=karaf.git;h=36a2bc4 https://gitbox.apache.org/repos/asf?p=
cvelistv5nvd
CVE-2018-11788CRITICALCVSS 9.8vAny Apache Karaf version prior to 4.1.7 and 4.2.22019-01-07
CVE-2018-11788 [CRITICAL] CWE-611 CVE-2018-11788: Apache Karaf provides a features deployer, which allows users to "hot deploy" a features XML by drop
Apache Karaf provides a features deployer, which allows users to "hot deploy" a features XML by dropping the file directly in the deploy folder. The features XML is parsed by XMLInputFactory class. Apache Karaf XMLInputFactory class doesn't contain any mitigation codes against XXE. This is a potential security risk as an user can inject external X
cvelistv5nvd
CVE-2018-11786HIGHCVSS 8.8vprior to 4.2.0 release2018-09-18
CVE-2018-11786 [HIGH] CWE-269 CVE-2018-11786: In Apache Karaf prior to 4.2.0 release, if the sshd service in Karaf is left on so an administrator
In Apache Karaf prior to 4.2.0 release, if the sshd service in Karaf is left on so an administrator can manage the running instance, any user with rights to the Karaf console can pivot and read/write any file on the file system to which the Karaf process user has access. This can be locked down a bit by using chroot to change the root directory to prot
cvelistv5nvd
CVE-2018-11787HIGHCVSS 8.1vprior to 3.0.9v4.0.x prior to 4.0.9+1 more2018-09-18
CVE-2018-11787 [HIGH] CWE-287 CVE-2018-11787: In Apache Karaf version prior to 3.0.9, 4.0.9, 4.1.1, when the webconsole feature is installed in Ka
In Apache Karaf version prior to 3.0.9, 4.0.9, 4.1.1, when the webconsole feature is installed in Karaf, it is available at .../system/console and requires authentication to access it. One part of the console is a Gogo shell/console that gives access to the command line console of Karaf via a Web browser, and when navigated to it is available at .../s
cvelistv5nvd
CVE-2016-8750MEDIUMCVSS 6.5vprior to 4.0.82018-02-19
CVE-2016-8750 [MEDIUM] CWE-90 CVE-2016-8750: Apache Karaf prior to 4.0.8 used the LDAPLoginModule to authenticate users to a directory via LDAP.
Apache Karaf prior to 4.0.8 used the LDAPLoginModule to authenticate users to a directory via LDAP. However, it did not encoding usernames properly and hence was vulnerable to LDAP injection attacks leading to a denial of service.
cvelistv5nvd