High
CVE-2022-40145
Apache Karaf could allow a remote attacker to execute arbitrary code on the system, caused by a LDAP injection flaw in the jaas.modules.src.main.java.porg.apache.karaf.jass.modules.jdbc.JDBCUtils#doCreateDatasource use InitialContext.lookup(jndiName) function. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the system.
Apache
Upgrade to the latest version of Apache Karaf, available from the Apache Website.