Impact
The vulnerability in the Hawtio operator allows an attacker who has edit access in any namespace to generate Service‑CA‑signed client certificates with an arbitrary Subject Common Name (CN). By supplying a custom Hawtio resource, the operator uses the OpenShift Service‑CA private signing key to mint a certificate that can impersonate any in‑cluster service identity. This can be used to subvert clients that trust the Service‑CA for authentication, such as Jolokia agents and other Service‑CA‑trusting components. The flaw therefore provides a path to covertly impersonate privileged services and potentially conduct further attacks on the cluster.
Affected Systems
Red Hat builds of Apache Camel – HawtIO 4 deployed in OpenShift environments. No specific version numbers are listed, so all instances of this operator are potentially affected.
Risk and Exploitability
The CVSS score of 9.9 marks this flaw as critical. The EPSS score is not available, so the likelihood of widespread exploitation is unknown, but the flaw is listed in no KEV catalog, implying no publicly known exploits yet. The attack vector likely requires an edit‑level user to create or modify a Hawtio custom resource; this inference is based on the description and is not directly stated in the input.
OpenCVE Enrichment