Apache Camel K 中存在“代码生成控制不当”(代码注入)漏洞。 在自定义资源配置中的 YAML 注入漏洞,允许授权的资源创建者(CR author)注入任意的 Kubernetes 对象,从而可能以 operator 的权限创建未授权的资源。 此问题影响 Apache Camel K 版本:2.0.0 至 2.9.2,以及 2.10.1 至 2.10.1。 建议用户升级到 2.9.3、2.10.2 或 2.11.0 版本,这些版本已修复该问题。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Camel K | 2.0.0 ~ 2.9.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-80354 | Apache Camel K: Camel K Builder trait mavenProfiles ValueSources resolve tenant-named secr | |
| CVE-2026-80351 | Apache Camel K: Camel K Tenant repositories reach Maven execution inside operator pod | |
| CVE-2026-84939 | Apache FreeMarker, Apache FreeMarker: A malformed locale may be exploitable for path trave | |
| CVE-2026-49362 | Apache Artemis, Apache ActiveMQ Artemis: Missing Authentication in CORE Protocol Handler A | |
| CVE-2026-49363 | Apache Artemis, Apache ActiveMQ Artemis: Pre-Authentication Information Disclosure in CORE | |
| CVE-2026-49364 | Apache Artemis, Apache Artemis, Apache ActiveMQ Artemis, Apache ActiveMQ Artemis: Pre-Auth | |
| CVE-2026-57822 | Apache Artemis, Apache ActiveMQ Artemis: Message-based management parameter deserializatio | |
| CVE-2026-57967 | Apache Artemis, Apache ActiveMQ Artemis: Missing authentication on CORE protocol session r | |
| CVE-2026-67593 | Apache Artemis, Apache Artemis, Apache ActiveMQ Artemis, Apache ActiveMQ Artemis: Pre-auth | |
| CVE-2026-75880 | Apache Artemis, Apache ActiveMQ Artemis: Message selector wildcard handling could lead to |
No comments yet