First published: Thu May 09 2019(Updated: )
Apache Karaf Config service provides a install method (via service or MBean) that could be used to travel in any directory and overwrite existing file. The vulnerability is low if the Karaf process user has limited permission on the filesystem. Any Apache Karaf version before 4.2.5 is impacted. User should upgrade to Apache Karaf 4.2.5 or later.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Karaf | <4.2.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-0226 is a vulnerability in the Apache Karaf Config service that allows an attacker to overwrite existing files by traveling to any directory.
The severity of CVE-2019-0226 is medium, with a severity value of 4.9.
An attacker can exploit CVE-2019-0226 by using the install method of the Apache Karaf Config service to travel to any directory and overwrite existing files.
All Apache Karaf versions before 4.2.5 are affected by CVE-2019-0226.
The impact of CVE-2019-0226 depends on the permissions of the Karaf process user. If the user has limited permissions on the filesystem, the impact is low.