Impact
A path traversal flaw arises during project commits when the submitted project file name is used directly as a path segment in the working copy. The flaw permits an authenticated user to craft a file name containing ../ sequences, thereby causing the file content to be written outside the intended project directory. Because the Karavan process can write to any folder under its permission set, the attacker can overwrite application configuration or class‑path files and subsequently execute arbitrary code within the Karavan container.
Affected Systems
The vulnerability affects Apache Camel Karavan versions starting from 3.18.0 up to, but not including, 4.22.1. Any installation of these releases is susceptible unless the project file API input is manually validated or the process permissions are restricted.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity, but the EPSS score is not available. The flaw is not listed in CISA’s KEV catalog. Exploitation requires authentication to the Karavan platform, and the attacker can target any writable location on the host. Once an arbitrary file is overwritten—particularly on the application classpath—remote code execution is possible.
OpenCVE Enrichment