CyberRota Analysis
AI-GeneratedA YAML injection vulnerability in Apache Camel K allows authorized users to inject arbitrary Kubernetes objects into custom resource configurations, potentially leading to unauthorized resource creation with the operator's privileges. This issue affects versions 2.0.0 through 2.9.2 and 2.10.1, making it critical for organizations using these versions to upgrade to 2.9.3, 2.10.2, or 2.11.0 to mitigate the risk. Kubernetes administrators and security teams should prioritize this vulnerability to protect their environments from potential exploitation.
Original NVD Description
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Camel K. A YAML injection vulnerability in custom resource configuration allows an authorized CR author to inject arbitrary Kubernetes objects, potentially enabling unauthorized resource creation with the privileges of the operator. This issue affects Apache Camel K: from 2.0.0 before 2.9.3, from 2.10.1 before 2.10.2. Users are recommended to upgrade to version 2.9.3, 2.10.2 or 2.11.0, which fixes the issue.