Author: jbonofre
Date: Mon Sep 28 15:30:54 2026
New Revision: 1938617
Log:
[scm-publish] Updating main website contents
Added:
karaf/site/production/security/cve-2026-91012.txt
Modified:
karaf/site/production/documentation.html
karaf/site/production/feed.xml
Modified: karaf/site/production/documentation.html
==============================================================================
--- karaf/site/production/documentation.html Mon Sep 28 14:10:34 2026
(r1938616)
+++ karaf/site/production/documentation.html Mon Sep 28 15:30:54 2026
(r1938617)
@@ -356,6 +356,13 @@
<div class="k-admonition">
<div class="k-admonition-icon"><i class="fas fa-shield-halved"></i></div>
<div>
+ <p>CVE-2026-91012: Apache Karaf: Path Traversal in Config Service Allows
Manager-to-Admin Privilege Escalation </p>
+ <a class="btn btn-outline-primary btn-sm"
href="/security/cve-2026-91012.txt">Notes »</a>
+ </div>
+ </div>
+ <div class="k-admonition">
+ <div class="k-admonition-icon"><i class="fas fa-shield-halved"></i></div>
+ <div>
<p>CVE-2026-92230: Apache Karaf: Improper release of ClassLoader
references via static ThreadLocal caching</p>
<a class="btn btn-outline-primary btn-sm"
href="/security/cve-2026-92230.txt">Notes »</a>
</div>
Modified: karaf/site/production/feed.xml
==============================================================================
--- karaf/site/production/feed.xml Mon Sep 28 14:10:34 2026
(r1938616)
+++ karaf/site/production/feed.xml Mon Sep 28 15:30:54 2026
(r1938617)
@@ -1 +1 @@
-<?xml version="1.0" encoding="utf-8"?><feed
xmlns="http://www.w3.org/2005/Atom" ><generator uri="https://jekyllrb.com/"
version="4.4.1">Jekyll</generator><link
href="https://karaf.apache.org/feed.xml" rel="self" type="application/atom+xml"
/><link href="https://karaf.apache.org/" rel="alternate" type="text/html"
/><updated>2026-09-28T04:43:43-05:00</updated><id>https://karaf.apache.org/feed.xml</id><title
type="html">Apache Karaf - The modulith runtime</title><subtitle>Karaf
provides modulith runtime for the enterprise, running on premise or on cloud.
Focus on your business code and applications, Apache Karaf deals with the
rest.</subtitle></feed>
\ No newline at end of file
+<?xml version="1.0" encoding="utf-8"?><feed
xmlns="http://www.w3.org/2005/Atom" ><generator uri="https://jekyllrb.com/"
version="4.4.1">Jekyll</generator><link
href="https://karaf.apache.org/feed.xml" rel="self" type="application/atom+xml"
/><link href="https://karaf.apache.org/" rel="alternate" type="text/html"
/><updated>2026-09-28T10:29:34-05:00</updated><id>https://karaf.apache.org/feed.xml</id><title
type="html">Apache Karaf - The modulith runtime</title><subtitle>Karaf
provides modulith runtime for the enterprise, running on premise or on cloud.
Focus on your business code and applications, Apache Karaf deals with the
rest.</subtitle></feed>
\ No newline at end of file
Added: karaf/site/production/security/cve-2026-91012.txt
==============================================================================
--- /dev/null 00:00:00 1970 (empty, because file is newly added)
+++ karaf/site/production/security/cve-2026-91012.txt Mon Sep 28 15:30:54
2026 (r1938617)
@@ -0,0 +1,50 @@
+-----BEGIN PGP SIGNED MESSAGE-----
+Hash: SHA256
+
+CVE-2026-91012: Apache Karaf: Path Traversal in Config Service Allows
Manager-to-Admin Privilege Escalation
+
+Severity: important
+
+Affected versions:
+
+- - Apache Karaf (org.apache.karaf.config.core.impl) before 4.4.12
+
+Description:
+
+org.apache.karaf.config.core.impl.ConfigRepositoryImpl#update(pid, properties),
+which backs the "config" MBean and the config:* shell commands, derives the
file
+it writes a configuration to from caller-supplied input without checking that
+the result stays inside ${karaf.etc}:
+
+ * if the submitted property map contains a felix.fileinstall.filename
entry, that value is turned directly into a File (getCfgFileFromProperty), so
it can point to any absolute path the Karaf process can write to;
+ * otherwise the configuration PID is concatenated verbatim into the target
file name (generateConfigFilename(): new File(karaf.etc, pid + ".cfg")), so a
PID containing ".." segments resolves outside ${karaf.etc}.
createFactoryConfiguration() has the same issue via the factory PID/alias.
+
+Both code paths are reachable by any caller holding the "manager" role under
Karaf's shipped command/JMX ACL (org.apache.karaf.command.acl.conf.cfg: "update
= manager"). Such a user can therefore write attacker-controlled content to any
file the Karaf process can write, including files the same ACL otherwise
reserves to "admin" (etc/users.properties, etc/*.acl.*.cfg,
etc/org.apache.karaf.management.cfg, and similar), allowing a manager-role user
to grant themselves the admin role or otherwise take over the container.
+
+ConfigMBeanImpl.install() and the config:install shell command already guarded
the equivalent risk on their own code path with a finalname.contains("..")
string check, but that check does not stop absolute paths or symlink-based
escapes, and it was never applied to ConfigRepositoryImpl.update() /
createFactoryConfiguration() at all.
+
+Credit:
+
+n0mi1k <[email protected]> (reporter)
+
+References:
+
+https://karaf.apache.org/
+https://www.cve.org/CVERecord?id=CVE-2026-91012
+-----BEGIN PGP SIGNATURE-----
+
+iQJPBAEBCAA5FiEEGqjPktQJpzOT0Lc2v/LuQsgoLnYFAmq6hrwbFIAAAAAABAAO
+bWFudTIsMi41KzEuMTIsMCwzAAoJEL/y7kLIKC52i5YP/17D5+5aLF0nlVld+QU2
+QmhlL7QvkidS6SnLVj709f5lXqdlbM3NfNkxjNC3gWMblcVogAFa21QLgOOrPq0T
+K3EOpB/5vN0ak148NvUbrB9RhBHj1GlvWpwgsloO4LHgZHryAbGoXqI7/qzVyQhy
+8MGPDwMvG8OYuTtDVaDDvWDlcu2nr1PuVBt5twmYfIEFS+3Gpmwp+uiI50EQh/Rq
+cJhA643XrKAf9+3SrmsxltqG7gtEnlwoDBeYRjJ+FNMSUNm2vX3RbhEY4Qsa5syk
+FGsBm+ish1DipWzQnSYL67uWMIzrywyIFEJU12dOQnvxcoNDYdhnXQGSnxSCnShE
+P9xJMYeyvpMPLy5AjGQ0XC9cy0RyGPForhe82fLmrYBcYL5vEwwOgt/9AqJ7+HeC
+tz0MuUFLUuMw7R+G7w6geN8HSv5arXfW3iK2X5hw9IK2X7dYrx52C+6hFxpCoy/E
+n7mz5MHxkltRoAPzO4RjYYZQRCZSxIpFXQ9TPW2zrk8uR3SuE0v/xsM8MXP7GKyp
+P45Aa3XCABHvAop8wOtCHYwH+7xaljUKck75qcmxpp4RiRA3UoSvxnkUGy96cm6h
+esCpo4MpbqEOa8O+7u8aIV3zX81fnBH6pjXQYaER7WMw3WQkvE5hs8nf9/1TcfO/
+h2aXf0lM+O/QXhrKSWZaJ1Dv
+=LDcl
+-----END PGP SIGNATURE-----