Impact
An authorization bypass exists when a tenant's custom resource resolution allows the tenant to reference secrets by name in the operator namespace. The vulnerability is a user‑controlled key flaw (CWE‑639) that enables a tenant to read or reference secrets that belong to other tenants or operator components, potentially exposing sensitive information or credentials.
Affected Systems
The Apache Camel K product, maintained by the Apache Software Foundation, is affected. Versions starting from 2.0.0 up to but not including 2.9.3 and from 2.10.1 up to but not including 2.10.2 are vulnerable. Users on these versions should verify their installation is within the stated ranges.
Risk and Exploitability
The CVSS score is not listed, but the impact is high because unauthorized secrets are exposed to any tenant that crafts a custom resource. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting no known mass exploitation yet. However, the attack vector is likely internal or among multiple tenant users, as any tenant with the ability to submit resources can trigger the flaw, making the risk significant in multi‑tenant deployments.
OpenCVE Enrichment