{"id":"GHSA-544x-2jx9-4pfg","summary":"Path traversal in Apache Karaf","details":"Apache Karaf obr:* commands and run goal on the karaf-maven-plugin have partial path traversal which allows to break out of expected folder. The risk is low as obr:* commands are not very used and the entry is set by user. This has been fixed in revision: https://gitbox.apache.org/repos/asf?p=karaf.git;h=36a2bc4 https://gitbox.apache.org/repos/asf?p=karaf.git;h=52b70cf Mitigation: Apache Karaf users should upgrade to 4.2.15 or 4.3.6 or later as soon as possible, or use correct path. JIRA Tickets: https://issues.apache.org/jira/browse/KARAF-7326","aliases":["CVE-2022-22932"],"modified":"2023-11-08T04:08:14.505362Z","published":"2022-01-28T22:25:03Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2022-01-27T23:10:36Z","nvd_published_at":"2022-01-26T11:15:00Z","cwe_ids":["CWE-22"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-22932"},{"type":"WEB","url":"https://github.com/apache/karaf/pull/1485"},{"type":"WEB","url":"https://gitbox.apache.org/repos/asf?p=karaf.git;h=36a2bc4"},{"type":"WEB","url":"https://gitbox.apache.org/repos/asf?p=karaf.git;h=52b70cf"},{"type":"PACKAGE","url":"https://github.com/apache/karaf"},{"type":"WEB","url":"https://issues.apache.org/jira/browse/KARAF-7326"},{"type":"WEB","url":"https://karaf.apache.org/security/cve-2022-22932.txt"}],"affected":[{"package":{"name":"org.apache.karaf:apache-karaf","ecosystem":"Maven","purl":"pkg:maven/org.apache.karaf/apache-karaf"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.3.0"},{"fixed":"4.3.6"}]}],"versions":["4.3.0","4.3.1","4.3.2","4.3.3","4.3.4","4.3.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-544x-2jx9-4pfg/GHSA-544x-2jx9-4pfg.json"}},{"package":{"name":"org.apache.karaf:apache-karaf","ecosystem":"Maven","purl":"pkg:maven/org.apache.karaf/apache-karaf"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.2.15"}]}],"versions":["2.0.0","2.1.0","2.1.1","2.1.2","2.1.3","2.1.4","2.1.5","2.1.6","2.2.0","2.2.1","2.2.10","2.2.11","2.2.2","2.2.3","2.2.4","2.2.5","2.2.6","2.2.7","2.2.8","2.2.9","2.3.0","2.3.1","2.3.10","2.3.11","2.3.12","2.3.2","2.3.3","2.3.4","2.3.5","2.3.6","2.3.7","2.3.8","2.3.9","2.4.0","2.4.1","2.4.2","2.4.3","2.4.4","3.0.0","3.0.0.RC1","3.0.1","3.0.10","3.0.2","3.0.3","3.0.4","3.0.5","3.0.6","3.0.7","3.0.8","3.0.9","4.0.0","4.0.0.M1","4.0.0.M2","4.0.0.M3","4.0.1","4.0.10","4.0.2","4.0.3","4.0.4","4.0.5","4.0.6","4.0.7","4.0.8","4.0.9","4.1.0","4.1.1","4.1.2","4.1.3","4.1.4","4.1.5","4.1.6","4.2.0","4.2.0.M1","4.2.0.M2","4.2.1","4.2.10","4.2.11","4.2.12","4.2.13","4.2.14","4.2.3","4.2.4","4.2.5","4.2.6","4.2.7","4.2.8","4.2.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-544x-2jx9-4pfg/GHSA-544x-2jx9-4pfg.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}]}