Impact
Apache Camel Karavan processes a project’s kubernetes.yaml file and applies every contained resource to the cluster without validating resource kinds or filtering security‑sensitive pod options. This flaw allows an authenticated user of any role to instruct Karavan to create arbitrary Kubernetes resources, including pods that enable hostNetwork, hostPID, hostIPC, hostPath volumes, host ports, privileged containers, privilege escalation or added capabilities. The resulting privileged containers could provide an attacker with elevated privileges, potentially enabling container escape or execution of arbitrary code on cluster nodes.
Affected Systems
The vulnerability affects Apache Software Foundation’s Apache Camel Karavan for all releases from 4.0.0 through and excluding 4.22.1. No other vendors or products are impacted.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity impact, reflecting the critical nature of executing arbitrary resources with elevated privileges. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, so an exact exploitation probability cannot be quantified. Attackers only need authenticated access to Karavan’s deployment process; the flaw leverages the service account’s existing cluster permissions, enabling a wide range of high‑impact actions without additional exploit development.
OpenCVE Enrichment