{"id":"CVE-2022-22932","details":"Apache Karaf obr:* commands and run goal on the karaf-maven-plugin have partial path traversal which allows to break out of expected folder. The risk is low as obr:* commands are not very used and the entry is set by user. This has been fixed in revision: https://gitbox.apache.org/repos/asf?p=karaf.git;h=36a2bc4 https://gitbox.apache.org/repos/asf?p=karaf.git;h=52b70cf Mitigation: Apache Karaf users should upgrade to 4.2.15 or 4.3.6 or later as soon as possible, or use correct path. JIRA Tickets: https://issues.apache.org/jira/browse/KARAF-7326","aliases":["GHSA-544x-2jx9-4pfg"],"modified":"2026-04-10T04:44:35.806484Z","published":"2022-01-26T11:15:09.583Z","references":[{"type":"ADVISORY","url":"https://karaf.apache.org/security/cve-2022-22932.txt"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/karaf","events":[{"introduced":"0"},{"fixed":"27c8ec4d55208ef58de2698cd89580d8b3478d55"},{"introduced":"65bd88e8149ba6e013665a238dfa32b92465f1c4"},{"fixed":"fa2562d583197ad41785a451144d58b148299858"}],"database_specific":{"versions":[{"introduced":"0"},{"fixed":"4.2.15"},{"introduced":"4.3.0"},{"fixed":"4.3.6"}]}}],"versions":["karaf-3.0.0","karaf-4.0.0.M1","karaf-4.0.0.M2","karaf-4.0.1","karaf-4.0.2","karaf-4.0.3","karaf-4.0.4","karaf-4.1.0","karaf-4.1.1","karaf-4.2.0","karaf-4.2.0.M1","karaf-4.2.0.M2","karaf-4.2.1","karaf-4.2.10","karaf-4.2.11","karaf-4.2.12","karaf-4.2.13","karaf-4.2.14","karaf-4.2.2","karaf-4.2.3","karaf-4.2.4","karaf-4.2.5","karaf-4.2.6","karaf-4.2.7","karaf-4.2.8","karaf-4.2.9","karaf-4.3.0","karaf-4.3.1","karaf-4.3.2","karaf-4.3.3","karaf-4.3.4","karaf-4.3.5"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-22932.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}]}