← Back

CVE-2019-0226

nvd nist
Published: May 9, 2019Modified: Jun 17, 2026

JSON object

Loading...
4.9
Vector
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Exploitability: 1.2 / Impact: 3.6
Source: NVD

Description

Apache Karaf Config service provides a install method (via service or MBean) that could be used to travel in any directory and overwrite existing file. The vulnerability is low if the Karaf process user has limited permission on the filesystem. Any Apache Karaf version before 4.2.5 is impacted. User should upgrade to Apache Karaf 4.2.5 or later.

Affected (1)

Products: Apache: Karaf
1 product
Karaf
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 4.2.5

Timeline

No history available yet.