CyberRota Analysis
AI-GeneratedAn authorization bypass vulnerability in Apache Camel K allows tenants to access secrets from the operator namespace by referencing them by name, potentially compromising the confidentiality of secrets belonging to other tenants or operator components. Organizations using affected versions (2.0.0 to 2.9.2 and 2.10.1) should prioritize upgrading to versions 2.9.3, 2.10.2, or 2.11.0 to mitigate this risk. This issue is particularly critical for multi-tenant environments where sensitive data isolation is essential.
Original NVD Description
Authorization bypass through User-Controlled key vulnerability in Apache Camel K. An authorization vulnerability in custom resource resolution allows a tenant to reference secrets by name in the operator namespace, potentially exposing secrets belonging to other tenants or operator components. This issue affects Apache Camel K: from 2.0.0 before 2.9.3, from 2.10.1 before 2.10.2. Users are recommended to upgrade to version 2.9.3, 2.10.2 or 2.11.0, which fixes the issue.
Related CVEs
Other vulnerabilities affecting the same vendor(s)