Apache Karaf 的 类在长期存活的容器线程中,将 XML 解析器和转换器工厂缓存于静态的 字段中。由于 中的值的生命周期超出了创建它的 OSGi Bundle 的生命周期,反复执行 Bundle 或 Feature 的安装、更新或刷新操作时,可能导致后续 Bundle 的 ClassLoader 被持续保留在内存中且无法被垃圾回收机制清理,从而引发 Metaspace 无限制增长,最终导致 Karaf 实例拒绝服务(DoS)。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache Karaf | < 4.4.11 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Karaf | 0 ~ 4.4.11 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet