CVE-2014-0219: Apache Karaf

Medium severity, CVSS 5.5. EPSS: 0.7% chance of exploitation in the next 30 days.

Apache Karaf before 4.0.10 enables a shutdown port on the loopback interface, which allows local users to cause a denial of service (shutdown) by sending a shutdown command to all listening high ports.

Affected products

  • Apache Karaf: before 4.0.10 (fixed in 4.0.10)

Published 2017-11-15. Last modified 2026-06-17.