Impact
An authorization bypass exists when a tenant's custom resource resolution allows the tenant to reference secrets by name in the operator namespace. The vulnerability is a user‑controlled key flaw (CWE‑639) that enables a tenant to read or reference secrets that belong to other tenants or operator components, potentially exposing sensitive information or credentials.
Affected Systems
The Apache Camel K product, maintained by the Apache Software Foundation, is affected. Versions starting from 2.0.0 up to but not including 2.9.3 and from 2.10.1 up to but not including 2.10.2 are vulnerable. Users on these versions should verify their installation is within the stated ranges.
Risk and Exploitability
The CVSS score is 8.1, indicating a high severity for authorization bypass. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, suggesting no known mass exploitation yet. However, the attack vector is likely internal or among multiple tenant users, as any tenant with the ability to submit resources can trigger the flaw, making the risk significant in multi‑tenant deployments.
OpenCVE Enrichment