Impact
This vulnerability is an improper neutralization of directives in dynamically evaluated code (eval injection). Tenant‑controlled repository content can influence the execution of Maven configuration inside the Camel K operator pod, allowing tenants to run arbitrary code with the operator’s privileges. The weakness corresponds to CWE‑95 and can compromise the confidentiality, integrity, and availability of the underlying Kubernetes cluster.
Affected Systems
The bug affects Apache Camel K versions prior to 2.9.3 (including 2.0.0 up to 2.9.2) and prior to 2.10.2 (including 2.10.1). The upstream project recommends upgrading to 2.9.3, 2.10.2, or the newer 2.11.0 release to remove the flaw.
Risk and Exploitability
The CVSS rating is not published, and an EPSS score is unavailable, but the capability to execute arbitrary code as the operator makes this a high‑risk flaw. It has not yet been added to the CISA KEV list. Attackers with the ability to supply or influence tenant repository content can inject malicious Maven directives, leading to code execution inside the operator pod. Visibility of the attack vector is inferred from the description; no public proof‑of‑concepts are cited in the advisory.
OpenCVE Enrichment