Apache Karaf CVE-2018-11787 Authentication Bypass Vulnerability
BID:107657
Info
Apache Karaf CVE-2018-11787 Authentication Bypass Vulnerability
| Bugtraq ID: | 107657 |
| Class: | Access Validation Error |
| CVE: |
CVE-2018-11787 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 18 2018 12:00AM |
| Updated: | Sep 18 2018 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Redhat OpenStack Platform 9.0 Redhat OpenStack Platform 8.0 (Liberty) Redhat OpenStack Platform 12 Redhat OpenStack Platform 10 Redhat Jboss Fuse Service Works 6.0 Apache Karaf 4.1 Apache Karaf 4.0.8 Apache Karaf 3.0.8 |
| Not Vulnerable: |
Apache Karaf 4.1.1 Apache Karaf 4.0.9 Apache Karaf 3.0.9 |
Discussion
Apache Karaf CVE-2018-11787 Authentication Bypass Vulnerability
Apache Karaf is prone to an authentication-bypass vulnerability.
An attacker can exploit this issue to bypass the authentication mechanism and perform unauthorized actions. This may lead to further attacks.
Versions prior to Karaf 3.0.9, Karaf 4.0.9, and Karaf 4.1.1 are vulnerable.
Apache Karaf is prone to an authentication-bypass vulnerability.
An attacker can exploit this issue to bypass the authentication mechanism and perform unauthorized actions. This may lead to further attacks.
Versions prior to Karaf 3.0.9, Karaf 4.0.9, and Karaf 4.1.1 are vulnerable.
Exploit / POC
Apache Karaf CVE-2018-11787 Authentication Bypass Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Apache Karaf CVE-2018-11787 Authentication Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Apache Karaf CVE-2018-11787 Authentication Bypass Vulnerability
References:
References:
- Apache Homepage (Apache)
- Bug 1631100 (CVE-2018-11787) - CVE-2018-11787 karaf: Authentication bypass acce (Redhat)
- CVE-2018-11787 (Redhat)
- CVE-2018-11787: Apache Karaf unsecure access to Gogo shell in the webconsole (Apache)
- CVS-2018-11787: Apache Karaf unsecure access to Gogo shell in the webconsole (Apache)
- Unsecured access to gogo console over web (Apache)