Impact
An improper neutralization of directives in dynamically evaluated Maven configuration allows tenant-controlled repository content to influence code execution within the operator pod, potentially enabling tenants to execute arbitrary code with the privileges of the operator. The flaw satisfies CWE‑95 and could compromise confidentiality, integrity, and availability across the cluster.
Affected Systems
The vulnerability affects Apache Camel K versions 2.0.0 through 2.9.2, and version 2.10.1. Versions 2.9.3 and later, 2.10.2 and later, and 2.11.0 are unaffected.
Risk and Exploitability
The CVSS score is 9.8 and the EPSS score of < 1% indicates a very low exploitation probability. The flaw is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is that an attacker controlling a tenant’s repository can inject malicious Maven directives, which are then processed by the operator pod, leading to code execution. No public proof‑of‑impact is sufficient.
OpenCVE Enrichment