Unsecured Gogo Console in Apache Karaf Webconsole Feature
CVE-2018-11787
8.1HIGH
What is CVE-2018-11787?
In specific versions of Apache Karaf, the installation of the webconsole feature exposes the Gogo shell to the web. While direct access to the Gogo URL requires authentication, if the Pax Web Extender Whiteboard is installed, the Gogo console becomes accessible at an unsecured endpoint. This allows unauthenticated users to gain access to the Karaf command line interface, potentially compromising system security. To mitigate this vulnerability, users should consider disabling the Gogo shell or the Pax Web Extender Whiteboard, though doing so may impact the functionality of other dependent components.
Affected Version(s)
Apache Karaf prior to 3.0.9
Apache Karaf 4.0.x prior to 4.0.9
Apache Karaf 4.1.x prior to 4.1.1