VYPR

Maven package

org.apache.karaf/karaf

pkg:maven/org.apache.karaf/karaf

Vulnerabilities (1)

  • CVE-2019-0191Mar 20, 2019
    affected < 4.2.3fixed 4.2.3

    Apache Karaf kar deployer reads .kar archives and extracts the paths from the "repository/" and "resources/" entries in the zip file. It then writes out the content of these paths to the Karaf repo and resources directories. However, it doesn't do any validation on the paths in t