PT-2026-108893 · Apache · Apache Camel Karavan
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Apache Camel Karavan versions 3.18.0 through 4.22.0
Description
An authenticated user with any role can exploit a path traversal issue where a project file name provided via the project file API is used without proper validation when writing the project to a working copy for a Git commit. By including
../ sequences in the file name, an attacker can write file content outside the intended project directory to any location writable by the process. This can lead to the overwriting of application configuration or files on the application classpath, potentially resulting in remote code execution within the container.Recommendations
Upgrade to version 4.22.1.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Camel Karavan