Karaf is a lightweight, powerful, and enterprise ready modulith runtime. It provides all the ecosystem and bootstrapping options you need for your applications.
Apache Karaf's JAAS LDAP login module is affected by LDAP filter injection. The user and role LDAP search filters are built in LDAPCache by string substitution: each placeholder (%u for the username, %dn for the user DN, %fqdn for the fully qualified DN) is inserted with java.util.regex Matcher.quoteReplacement followed by doubling backslashes, which is regex-replacement escaping, not RFC 2254 / RFC 4515 LDAP filter escaping. The filter construction itself therefore does not neutralize LDAP metacharacters, it relies on the caller to have encoded the values. The login module does pre-encode the username with Util.doRFC2254Encoding before the user search, but the role search filter also substitutes the DN values (%dn, %fqdn) with no LDAP escaping, and the filter builder performs none of its own. As a result a value that reaches the filter without prior encoding is not neutralized and can alter the LDAP query.