PT-2026-108894 · Apache · Apache Camel Karavan
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Apache Camel Karavan versions 4.0.0 through 4.22.0
Description
Improper input validation occurs when a deployment is started. The software unmarshals a project's
kubernetes.yaml and applies all contained resources to the cluster without restricting resource kinds, rejecting security-sensitive pod options, or pinning the target namespace. An authenticated user with any role can cause the application of arbitrary Kubernetes resources accessible to its service account, including pods requesting hostNetwork, hostPID, hostIPC, hostPath volumes, host ports, privileged containers, privilege escalation, or added capabilities.Recommendations
Upgrade to version 4.22.1.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Camel Karavan