Apache Karaf obr:* commands and run goal on the karaf-maven-plugin have partial path traversal which allows to break out of expected folder. The risk is low as obr:* commands are not very used and the entry is set by user. This has been fixed in revision: https://gitbox.apache.org/repos/asf?p=karaf.git;h=36a2bc4 https://gitbox.apache.org/repos/asf?p=karaf.git;h=52b70cf Mitigation: Apache Karaf users should upgrade to 4.2.15 or 4.3.6 or later as soon as possible, or use correct path. JIRA Tickets: https://issues.apache.org/jira/browse/KARAF-7326
Advisories
Source ID Title
EUVD EUVD EUVD-2022-0454 Apache Karaf obr:* commands and run goal on the karaf-maven-plugin have partial path traversal which allows to break out of expected folder. The risk is low as obr:* commands are not very used and the entry is set by user. This has been fixed in revision: https://gitbox.apache.org/repos/asf?p=karaf.git;h=36a2bc4 https://gitbox.apache.org/repos/asf?p=karaf.git;h=52b70cf Mitigation: Apache Karaf users should upgrade to 4.2.15 or 4.3.6 or later as soon as possible, or use correct path. JIRA Tickets: https://issues.apache.org/jira/browse/KARAF-7326
Github GHSA Github GHSA GHSA-544x-2jx9-4pfg Path traversal in Apache Karaf
Fixes

Solution

No solution given by the vendor.


Workaround

Apache Karaf users should upgrade to 4.2.15 or 4.3.6 or later as soon as possible, or use correct path.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2024-08-03T03:28:42.479Z

Reserved: 2022-01-10T00:00:00

Link: CVE-2022-22932

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-01-26T11:15:09.583

Modified: 2024-11-21T06:47:38.223

Link: CVE-2022-22932

cve-icon Redhat

Severity : Low

Publid Date: 2022-01-09T00:00:00Z

Links: CVE-2022-22932 - Bugzilla

cve-icon OpenCVE Enrichment

No data.