CVE-2014-0219 describes a denial-of-service vulnerability in Apache Karaf versions prior to 4.0.10. The vulnerability allows a local attacker to shut down the Karaf instance by sending a shutdown command to the loopback interface's high ports. Rated with a CVSS score of 5.5 (Medium), this vulnerability has a local attack vector and low attack complexity, enabling an unauthenticated local user to achieve a high impact denial of service. There is no impact on confidentiality or integrity. There is currently no evidence of active exploitation, nor is public exploit code available in Metasploit or ExploitDB. The vulnerability has received minimal community attention, with no social media discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.0.10CPE matchmatch criteria | cpe:2.3:a:apache:karaf:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.