This is an automated email from the ASF dual-hosted git repository.

jbonofre pushed a commit to branch trunk
in repository https://gitbox.apache.org/repos/asf/karaf-site.git


The following commit(s) were added to refs/heads/trunk by this push:
     new 44795ad  Disclose CVE-2026-90979
44795ad is described below

commit 44795ad51fedbe716e137de1ab6c6667bb1d99c6
Author: JB Onofré <[email protected]>
AuthorDate: Mon Sep 28 10:26:35 2026 +0200

    Disclose CVE-2026-90979
---
 documentation.html          |  9 ++++++++-
 security/cve-2026-90979.txt | 33 +++++++++++++++++++++++++++++++++
 2 files changed, 41 insertions(+), 1 deletion(-)

diff --git a/documentation.html b/documentation.html
index 2ebd738..1954171 100644
--- a/documentation.html
+++ b/documentation.html
@@ -221,6 +221,13 @@ permalink: /documentation
       <a class="btn btn-outline-primary btn-sm" 
href="/security/cve-2026-92230.txt">Notes &raquo;</a>
     </div>
   </div>
+  <div class="k-admonition">
+    <div class="k-admonition-icon"><i class="fas fa-shield-halved"></i></div>
+    <div>
+      <p>CVE-2026-90979: Apache Karaf: LDAP filter injection in JAAS LDAP 
login modules</p>
+      <a class="btn btn-outline-primary btn-sm" 
href="/security/cve-2026-90979.txt">Notes &raquo;</a>
+    </div>
+  </div>
 
   <!-- ARTICLES -->
   <h2 class="k-section-heading"><i class="fas fa-book-open 
k-section-icon"></i> Articles</h2>
@@ -329,4 +336,4 @@ permalink: /documentation
     <a class="k-link-item" href="https://fpapon.github.io/";>Francois Papon's 
Blog</a>
   </div>
 
-</div>
\ No newline at end of file
+</div>
diff --git a/security/cve-2026-90979.txt b/security/cve-2026-90979.txt
new file mode 100644
index 0000000..e0bb914
--- /dev/null
+++ b/security/cve-2026-90979.txt
@@ -0,0 +1,33 @@
+CVE-2026-90979: Apache Karaf: LDAP filter injection in JAAS LDAP login modules
+
+Severity: moderate
+
+Affected versions:
+
+- Apache Karaf before 4.4.12
+
+Description:
+
+LDAPCache and LDAPBackingEngine build LDAP search filters for user lookup and 
role lookup by textually substituting the placeholders %u, %dn, and %fqdn 
(drawn from the login name, the resolved user DN, and its fully qualified 
namespace form) into administrator-configured filter templates (userFilter, 
roleFilter). Before the fix, the only sanitization applied to the substituted 
value was double backslashed:
+
+filter = filter.replaceAll(Pattern.quote("%u"), 
Matcher.quoteReplacement(user));
+filter = filter.replace("\\", "\\\\");
+
+This does not escape the other characters RFC 4515 requires escaping in an 
LDAP search filter: *, (, ), and NUL. A login name containing any of these can 
change the structure of the resulting filter rather than being matched as a 
literal value (e.g. a crafted username can turn an equality match into a 
wildcard match, or close/reopen filter clauses), widening what the search 
returns and potentially causing a login or role lookup to match an LDAP entry 
other than the intended one, over-gra [...]
+
+It's not exploitable through every entry points: LDAPLoginModule and 
LDAPPubkeyLoginModule both called Util.doRFC2254Encoding() (correct RFC 4515 
escaping) on the login name before handing it to LDAPCache, which masked the 
missing escaping in LDAPCache for those two call paths. Using LDAPCache 
directly (bypassing the login modules) does not reproduce through the normal 
LDAPLoginModule/LDAPPubkeyLoginModule authentication flow for this reason. It 
does reproduce through two other call path [...]
+
+  *  GSSAPILdapLoginModule passes the NameCallback name straight through, 
unescaped.
+  *  LDAPBackingEngine (listRoles) passes principal.getName() straight 
through, unescaped.
+
+This issue is being tracked as https://github.com/apache/karaf/pull/2880 
+
+Credit:
+
+Gjoko Krstic <[email protected]> (reporter)
+
+References:
+
+https://karaf.apache.org/
+https://www.cve.org/CVERecord?id=CVE-2026-90979
+https://issues.apache.org/jira/browse/https://github.com/apache/karaf/pull/2880

Reply via email to