Impact
A flaw in the hawtio-operator causes the entire Route object, including the TLS private key in PEM format, to be serialized to JSON and written to the operator’s standard output when debug log level 1 or higher is enabled. The exposure of private key material constitutes a confidentiality breach, potentially allowing an attacker to decrypt traffic or impersonate the service. The vulnerability is a classic example of sensitive data exposure via logging (CWE-532).
Affected Systems
Red Hat build of Apache Camel – HawtIO 4 is affected. No specific sub‑versions are listed; all installations of this product that enable debug logging at level 1 or higher are at risk.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate severity. The EPSS score is below 1 %, indicating that exploitation is unlikely but possible. The vulnerability is not listed in the CISA KEV catalog, so there is no known active exploitation yet. The attack vector is local to the operator pod: an attacker with access to pod logs (e.g., anyone with pod/log permissions in the openshift‑operators namespace) can retrieve the exposed key. The requirement of debug logging is a low threshold commonly enabled during troubleshooting, so the risk is elevated in environments where debugging is used frequently.
OpenCVE Enrichment