
Cloud Vulnerability DB
A community-led vulnerabilities database
In Apache Karaf, a vulnerability (CVE-2020-11980) was discovered where JMX authentication takes place using JAAS and authorization takes place using ACL files. The vulnerability affects all versions of Apache Karaf prior to 4.2.9, allowing a remote client with viewer role privileges to create MBeans from arbitrary URLs (Karaf Security).
The vulnerability exists in the JMX authentication mechanism where users with 'viewer' role can call get* methods as defined in 'etc/jmx.acl.cfg'. This allows potential attackers to create a javax.management.loading.MLet MBean and use it to create new MBeans from arbitrary URLs. While the attack ultimately fails as the 'viewer' role doesn't have permission to invoke on the MBean, it could be used as a Server-Side Request Forgery (SSRF) style attack and allows privilege escalation by polluting the MBean registry (Karaf Security).
The vulnerability has been classified as having a low severity impact. While it doesn't allow full system compromise, it enables privilege escalation by allowing 'viewer' role users to pollute the MBean registry and potentially execute SSRF-style attacks (Karaf Security).
The vulnerability requires an attacker to have authenticated access with a 'viewer' role in the system. The exploit involves calling the MLet getMBeansFromURL method, which attempts to fetch MBeans from remote servers (Karaf Security).
Users are advised to upgrade to Apache Karaf version 4.2.9 or later. Alternatively, administrators can implement new JMX ACL configurations in the etc configuration to restrict access. The vulnerability has been fixed in specific revisions of the codebase (Karaf Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."