Author: jbonofre
Date: Mon Sep 28 15:30:54 2026
New Revision: 1938617

Log:
[scm-publish] Updating main website contents

Added:
   karaf/site/production/security/cve-2026-91012.txt
Modified:
   karaf/site/production/documentation.html
   karaf/site/production/feed.xml

Modified: karaf/site/production/documentation.html
==============================================================================
--- karaf/site/production/documentation.html    Mon Sep 28 14:10:34 2026        
(r1938616)
+++ karaf/site/production/documentation.html    Mon Sep 28 15:30:54 2026        
(r1938617)
@@ -356,6 +356,13 @@
   <div class="k-admonition">
     <div class="k-admonition-icon"><i class="fas fa-shield-halved"></i></div>
     <div>
+      <p>CVE-2026-91012: Apache Karaf: Path Traversal in Config Service Allows 
Manager-to-Admin Privilege Escalation </p>
+      <a class="btn btn-outline-primary btn-sm" 
href="/security/cve-2026-91012.txt">Notes &raquo;</a>
+    </div>
+  </div>
+  <div class="k-admonition">
+    <div class="k-admonition-icon"><i class="fas fa-shield-halved"></i></div>
+    <div>
       <p>CVE-2026-92230: Apache Karaf: Improper release of ClassLoader 
references via static ThreadLocal caching</p>
       <a class="btn btn-outline-primary btn-sm" 
href="/security/cve-2026-92230.txt">Notes &raquo;</a>
     </div>

Modified: karaf/site/production/feed.xml
==============================================================================
--- karaf/site/production/feed.xml      Mon Sep 28 14:10:34 2026        
(r1938616)
+++ karaf/site/production/feed.xml      Mon Sep 28 15:30:54 2026        
(r1938617)
@@ -1 +1 @@
-<?xml version="1.0" encoding="utf-8"?><feed 
xmlns="http://www.w3.org/2005/Atom"; ><generator uri="https://jekyllrb.com/"; 
version="4.4.1">Jekyll</generator><link 
href="https://karaf.apache.org/feed.xml"; rel="self" type="application/atom+xml" 
/><link href="https://karaf.apache.org/"; rel="alternate" type="text/html" 
/><updated>2026-09-28T04:43:43-05:00</updated><id>https://karaf.apache.org/feed.xml</id><title
 type="html">Apache Karaf - The modulith runtime</title><subtitle>Karaf 
provides modulith runtime for the enterprise, running on premise or on cloud. 
Focus on your business code and applications, Apache Karaf deals with the 
rest.</subtitle></feed>
\ No newline at end of file
+<?xml version="1.0" encoding="utf-8"?><feed 
xmlns="http://www.w3.org/2005/Atom"; ><generator uri="https://jekyllrb.com/"; 
version="4.4.1">Jekyll</generator><link 
href="https://karaf.apache.org/feed.xml"; rel="self" type="application/atom+xml" 
/><link href="https://karaf.apache.org/"; rel="alternate" type="text/html" 
/><updated>2026-09-28T10:29:34-05:00</updated><id>https://karaf.apache.org/feed.xml</id><title
 type="html">Apache Karaf - The modulith runtime</title><subtitle>Karaf 
provides modulith runtime for the enterprise, running on premise or on cloud. 
Focus on your business code and applications, Apache Karaf deals with the 
rest.</subtitle></feed>
\ No newline at end of file

Added: karaf/site/production/security/cve-2026-91012.txt
==============================================================================
--- /dev/null   00:00:00 1970   (empty, because file is newly added)
+++ karaf/site/production/security/cve-2026-91012.txt   Mon Sep 28 15:30:54 
2026        (r1938617)
@@ -0,0 +1,50 @@
+-----BEGIN PGP SIGNED MESSAGE-----
+Hash: SHA256
+
+CVE-2026-91012: Apache Karaf: Path Traversal in Config Service Allows 
Manager-to-Admin Privilege Escalation
+
+Severity: important 
+
+Affected versions:
+
+- - Apache Karaf (org.apache.karaf.config.core.impl) before 4.4.12
+
+Description:
+
+org.apache.karaf.config.core.impl.ConfigRepositoryImpl#update(pid, properties),
+which backs the "config" MBean and the config:* shell commands, derives the 
file
+it writes a configuration to from caller-supplied input without checking that
+the result stays inside ${karaf.etc}:
+
+  *  if the submitted property map contains a felix.fileinstall.filename 
entry, that value is turned directly into a File (getCfgFileFromProperty), so 
it can point to any absolute path the Karaf process can write to;
+  *  otherwise the configuration PID is concatenated verbatim into the target 
file name (generateConfigFilename(): new File(karaf.etc, pid + ".cfg")), so a 
PID containing ".." segments resolves outside ${karaf.etc}. 
createFactoryConfiguration() has the same issue via the factory PID/alias.
+
+Both code paths are reachable by any caller holding the "manager" role under 
Karaf's shipped command/JMX ACL (org.apache.karaf.command.acl.conf.cfg: "update 
= manager"). Such a user can therefore write attacker-controlled content to any 
file the Karaf process can write, including files the same ACL otherwise 
reserves to "admin" (etc/users.properties, etc/*.acl.*.cfg, 
etc/org.apache.karaf.management.cfg, and similar), allowing a manager-role user 
to grant themselves the admin role or otherwise take over the container.
+
+ConfigMBeanImpl.install() and the config:install shell command already guarded 
the equivalent risk on their own code path with a finalname.contains("..") 
string check, but that check does not stop absolute paths or symlink-based 
escapes, and it was never applied to ConfigRepositoryImpl.update() / 
createFactoryConfiguration() at all.
+
+Credit:
+
+n0mi1k <[email protected]> (reporter)
+
+References:
+
+https://karaf.apache.org/
+https://www.cve.org/CVERecord?id=CVE-2026-91012
+-----BEGIN PGP SIGNATURE-----
+
+iQJPBAEBCAA5FiEEGqjPktQJpzOT0Lc2v/LuQsgoLnYFAmq6hrwbFIAAAAAABAAO
+bWFudTIsMi41KzEuMTIsMCwzAAoJEL/y7kLIKC52i5YP/17D5+5aLF0nlVld+QU2
+QmhlL7QvkidS6SnLVj709f5lXqdlbM3NfNkxjNC3gWMblcVogAFa21QLgOOrPq0T
+K3EOpB/5vN0ak148NvUbrB9RhBHj1GlvWpwgsloO4LHgZHryAbGoXqI7/qzVyQhy
+8MGPDwMvG8OYuTtDVaDDvWDlcu2nr1PuVBt5twmYfIEFS+3Gpmwp+uiI50EQh/Rq
+cJhA643XrKAf9+3SrmsxltqG7gtEnlwoDBeYRjJ+FNMSUNm2vX3RbhEY4Qsa5syk
+FGsBm+ish1DipWzQnSYL67uWMIzrywyIFEJU12dOQnvxcoNDYdhnXQGSnxSCnShE
+P9xJMYeyvpMPLy5AjGQ0XC9cy0RyGPForhe82fLmrYBcYL5vEwwOgt/9AqJ7+HeC
+tz0MuUFLUuMw7R+G7w6geN8HSv5arXfW3iK2X5hw9IK2X7dYrx52C+6hFxpCoy/E
+n7mz5MHxkltRoAPzO4RjYYZQRCZSxIpFXQ9TPW2zrk8uR3SuE0v/xsM8MXP7GKyp
+P45Aa3XCABHvAop8wOtCHYwH+7xaljUKck75qcmxpp4RiRA3UoSvxnkUGy96cm6h
+esCpo4MpbqEOa8O+7u8aIV3zX81fnBH6pjXQYaER7WMw3WQkvE5hs8nf9/1TcfO/
+h2aXf0lM+O/QXhrKSWZaJ1Dv
+=LDcl
+-----END PGP SIGNATURE-----

Reply via email to