REDHAT-BUG-2046279: Path Traversal

Published Jan 26, 2022
·
Updated

Apache Karaf obr: commands and run goal on the karaf-maven-plugin have partial path traversal which allows to break out of expected folder. The risk is low as obr: commands are not very used and the entry is set by user.

This has been fixed in revision: https://gitbox.apache.org/repos/asf?p=karaf.git;h=36a2bc4 https://gitbox.apache.org/repos/asf?p=karaf.git;h=52b70cf

Mitigation: Apache Karaf users should upgrade to 4.2.15 or 4.3.6 or later as soon as possible, or use correct path.

JIRA Tickets: https://issues.apache.org/jira/browse/KARAF-7326

Affected Software

1 affected component
Apache Karaf<4.2.15, <4.3.6

Event History

Jan 26, 2022
Data Sourced
via Red Hat·02:02 PM
DescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2046279?

The severity of REDHAT-BUG-2046279 is low as the impacted obr:* commands are infrequently used and the entry is set by the user.

2

How do I fix REDHAT-BUG-2046279?

To fix REDHAT-BUG-2046279, you should update your Apache Karaf to a version later than 4.2.15 and 4.3.6.

3

Which versions of Apache Karaf are affected by REDHAT-BUG-2046279?

Apache Karaf versions 4.2.15 and earlier, as well as 4.3.6 and earlier, are affected by REDHAT-BUG-2046279.

4

What type of vulnerability is REDHAT-BUG-2046279?

REDHAT-BUG-2046279 is a partial path traversal vulnerability that allows users to break out of the expected folder structure.

5

Are there any workarounds for REDHAT-BUG-2046279?

There are no recommended workarounds for REDHAT-BUG-2046279; updating to a fixed version is advised.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203