Impact
The Hawtio operator writes the tenant-supplied spec.routeHostName value directly into the Kubernetes Route specification without performing validation or authorization checks. A user who can edit namespace resources—who normally cannot set custom Route hostnames—can use the operator as a confused deputy to claim any externally routable hostname. This allows the attacker to take over subdomains and, in combination with the auto-grant OAuthClient, hijack OAuth redirect flows. The weakness is a classic lack of input validation and authorization, identified as CWE‑441.
Affected Systems
The affected product is the Red Hat build of Apache Camel – HawtIO 4, with the identified vulnerability present in the 4.x release line. No further granularity on sub‑versions is provided.
Risk and Exploitability
The CVSS score of 6.3 indicates a moderate severity vulnerability, while an EPSS score of fewer than 1 % suggests that exploitation is unlikely in the wild at present. The CVE is not listed in the CISA KEV catalog. Exploitability requires the attacker to possess namespace‑edit rights and to manipulate Hawtio custom resources, which can be achieved through an existing user account with those permissions. The operator’s cluster‑wide routes/custom‑host:create permission and the absence of hostname validation create a clear attack path for hostname hijacking. Administrators are recommended to assess whether the necessary permissions are properly scoped and to apply mitigations promptly.
OpenCVE Enrichment