PT-2026-102461 · Apache · Apache Karaf
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Apache Karaf (affected versions not specified)
Description
An issue exists in the
org.apache.karaf.config.core.impl.ConfigRepositoryImpl#update(pid, properties) function, which supports the config MBean and config shell commands. The software derives the configuration file path from user-supplied input without verifying that the resulting path remains within the ${karaf.etc} directory. This occurs in two ways: if the property map includes a felix.fileinstall.filename entry, the value is converted directly into a File object, allowing it to point to any absolute path the process can write to; otherwise, the configuration PID is concatenated into the filename, allowing PIDs containing .. segments to resolve outside the intended directory. The createFactoryConfiguration() function is similarly affected via the factory PID or alias. Users with the manager role can exploit this to write controlled content to sensitive files, such as etc/users.properties or etc/org.apache.karaf.management.cfg, potentially granting themselves admin privileges or taking over the container.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
LPE
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Karaf