Vulnerability Description
Apache Karaf Config service provides a install method (via service or MBean) that could be used to travel in any directory and overwrite existing file. The vulnerability is low if the Karaf process user has limited permission on the filesystem. Any Apache Karaf version before 4.2.5 is impacted. User should upgrade to Apache Karaf 4.2.5 or later.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Karaf | < 4.2.5 |
Related Weaknesses (CWE)
References
- https://lists.apache.org/thread.html/1baa6f1df0e95fb1cd679067117354af2ab4423277d
- https://lists.apache.org/thread.html/r218c7e017af0a860ae21bf7ab77520fd2070c8f52d
- https://lists.apache.org/thread.html/1baa6f1df0e95fb1cd679067117354af2ab4423277d
- https://lists.apache.org/thread.html/r218c7e017af0a860ae21bf7ab77520fd2070c8f52d
FAQ
What is CVE-2019-0226?
CVE-2019-0226 is a vulnerability with a CVSS score of 4.9 (MEDIUM). Apache Karaf Config service provides a install method (via service or MBean) that could be used to travel in any directory and overwrite existing file. The vulnerability is low if the Karaf process us...
How severe is CVE-2019-0226?
CVE-2019-0226 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-0226?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Karaf.