CVE detail
CVE-2019-0226 — CVE-2019-0226
Published 2019-05-09 · Modified 2026-06-17 · Vendor apache · Product karaf · Source nvd
MEDIUM
severity
CVSS-derived band
0.0184
EPSS probability
exploitation probability, 30d
77.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Apache Karaf Config service provides a install method (via service or MBean) that could be used to travel in any directory and overwrite existing file. The vulnerability is low if the Karaf process user has limited permission on the filesystem. Any Apache Karaf version before 4.2.5 is impacted. User should upgrade to Apache Karaf 4.2.5 or later.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References