CVE-2019-0191
Apache Karaf kar deployer reads .kar archives and extracts the paths from the "repository/" and "resources/" entries in the zip file. It then writes out the content of these paths to the Karaf repo and resources directories. However, it doesn't do any validation on the paths in the zip file. This means that a malicious user could craft a .kar file with ".." directory names and break out of the directories to write arbitrary content to the filesystem. This is the "Zip-slip" vulnerability - https://snyk.io/research/zip-slip-vulnerability. This vulnerability is low if the Karaf process user has limited permission on the filesystem. Any Apache Karaf releases prior 4.2.3 is impacted.
Published at
2019-03-20
1033 days ago
Modified
2019-05-06
986 days ago
2019
Year
The year of the turtle
https://lists.apache.org/thread.html/cef9a2d4b547625e5214684283ac5c59c9d9740e092e777dc3f85070@%3Ccommits.karaf.apache.org%3E
MLIST:[karaf-commits] 20190506 [karaf-site] branch trunk updated: Publish CVE-2019-0226
https://lists.apache.org/thread.html/6856aa7ed7dd805eaf65d0e5e95027dda3b2307aacd1ab4a838c5cd1@%3Cuser.karaf.apache.org%3E
MLIST:[karaf-user] 20190307 [SECURITY] New security advisory for CVE-2019-0191 released for Apache Karaf
Vulnerability RAW
{
"Title": {
"_text": "CVE-2019-0191"
},
"Notes": {
"Note": [
{
"_text": "Apache Karaf kar deployer reads .kar archives and extracts the paths from the \"repository/\" and \"resources/\" entries in the zip file. It then writes out the content of these paths to the Karaf repo and resources directories. However, it doesn't do any validation on the paths in the zip file. This means that a malicious user could craft a .kar file with \"..\" directory names and break out of the directories to write arbitrary content to the filesystem. This is the \"Zip-slip\" vulnerability - https://snyk.io/research/zip-slip-vulnerability. This vulnerability is low if the Karaf process user has limited permission on the filesystem. Any Apache Karaf releases prior 4.2.3 is impacted."
},
{
"_text": "2019-03-20"
},
{
"_text": "2019-05-06"
}
]
},
"CVE": {
"_text": "CVE-2019-0191"
},
"References": {
"Reference": [
{
"URL": {
"_text": "http://www.securityfocus.com/bid/107462"
},
"Description": {
"_text": "BID:107462"
}
},
{
"URL": {
"_text": "https://lists.apache.org/thread.html/cef9a2d4b547625e5214684283ac5c59c9d9740e092e777dc3f85070@%3Ccommits.karaf.apache.org%3E"
},
"Description": {
"_text": "MLIST:[karaf-commits] 20190506 [karaf-site] branch trunk updated: Publish CVE-2019-0226"
}
},
{
"URL": {
"_text": "https://lists.apache.org/thread.html/6856aa7ed7dd805eaf65d0e5e95027dda3b2307aacd1ab4a838c5cd1@%3Cuser.karaf.apache.org%3E"
},
"Description": {
"_text": "MLIST:[karaf-user] 20190307 [SECURITY] New security advisory for CVE-2019-0191 released for Apache Karaf"
}
}
]
}
}