Impact
Apache Karaf's InstanceService implementation constructs a command line to launch child JVMs by concatenating user‑supplied javaOpts into a shell command. Because the value is not quoted, shell metacharacters such as ;, |, `, and $(…) are interpreted by /bin/sh or cscript, allowing an attacker who can invoke instance:create, instance:start, instance:restart, or the corresponding JMX operations to execute arbitrary commands with the credentials of the Karaf process. This is an OS command injection flaw, identified as CWE‑78, and provides full control over the host operating system.
Affected Systems
Both the service‑side and JMX interfaces of Apache Karaf expose this behavior. The vulnerability affects all deployments of Apache Karaf where the InstanceService is reachable, regardless of version, because no specific product version is listed. Administrators who grant users permission to run the instance:* commands or the InstanceMBean methods may inadvertently expose the injection vector.
Risk and Exploitability
Because the flaw relies on command‑line concatenation and unquoted input, exploiting it does not require complex prerequisites; an attacker with access to the Karaf command shell or JMX interface can inject shell metacharacters to run arbitrary commands. The CVSS score is not provided, but the lack of enforcement on the javaOpts parameter indicates a high‑risk vulnerability. EPSS is not available and KEV is not listed, yet the potential for remote command execution remains significant. Mitigations focus on restricting command access or treating the parameter as untrusted input.
OpenCVE Enrichment