Impact
The vulnerability is an improper control of code generation that allows a YAML injection in custom resource configuration. An authorized creator of a custom resource can inject arbitrary Kubernetes objects, which are then created with the privileges of the operator. This effectively permits the attacker to introduce malicious workloads or alter cluster configuration, compromising confidentiality, integrity and availability of the cluster.
Affected Systems
Apache Camel K from version 2.0.0 up to but not including 2.9.3, from 2.10.1 up to but not including 2.10.2, and any earlier releases are vulnerable. The vulnerability is tied to the Master trait serviceAccountName handling in Camel K custom resources.
Risk and Exploitability
The lack of formal control over injected YAML allows an attacker who can write a custom resource to execute arbitrary resource creation. The exploit requires only the ability to submit a custom resource, a permission that existing CR authors typically possess. Since Enterprise Score (EPSS) information is not available and the vulnerability is not listed in the CISA KEV catalog, precise exploitation likelihood cannot be quantified, but the impact is high and the attack vector is feasible from within the cluster. The CVSS score is not provided, yet the attack would let an attacker achieve full operator privileges within the used Kubernetes namespace.
OpenCVE Enrichment