CVE-2014-0219: Apache Karaf
Medium severity, CVSS 5.5. EPSS: 0.7% chance of exploitation in the next 30 days.
Apache Karaf before 4.0.10 enables a shutdown port on the loopback interface, which allows local users to cause a denial of service (shutdown) by sending a shutdown command to all listening high ports.
Affected products
- Apache Karaf: before 4.0.10 (fixed in 4.0.10)
Published 2017-11-15. Last modified 2026-06-17.