以下是该漏洞描述的中文翻译: Apache Camel K 中通过用户可控密钥实现的授权绕过漏洞 在自定义资源解析过程中存在的授权漏洞,允许租户在 operator 命名空间中通过名称引用 secrets(密钥),这可能暴露属于其他租户或 operator 组件的 secrets。 此问题影响以下版本的 Apache Camel K: 2.0.0 及之后但早于 2.9.3 的版本; 2.10.1 及之后但早于 2.10.2 的版本。 建议用户升级至以下版本以修复该问题: 2.9.3 2.10.2 2.11.0 --
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Camel K | 2.0.0 ~ 2.9.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-80351 | Apache Camel K: Camel K Tenant repositories reach Maven execution inside operator pod | |
| CVE-2026-80352 | Apache Camel K: Camel K Master trait serviceAccountName YAML injection lets CR author appl | |
| CVE-2026-84939 | Apache FreeMarker, Apache FreeMarker: A malformed locale may be exploitable for path trave | |
| CVE-2026-49362 | Apache Artemis, Apache ActiveMQ Artemis: Missing Authentication in CORE Protocol Handler A | |
| CVE-2026-49363 | Apache Artemis, Apache ActiveMQ Artemis: Pre-Authentication Information Disclosure in CORE | |
| CVE-2026-49364 | Apache Artemis, Apache Artemis, Apache ActiveMQ Artemis, Apache ActiveMQ Artemis: Pre-Auth | |
| CVE-2026-57822 | Apache Artemis, Apache ActiveMQ Artemis: Message-based management parameter deserializatio | |
| CVE-2026-57967 | Apache Artemis, Apache ActiveMQ Artemis: Missing authentication on CORE protocol session r | |
| CVE-2026-67593 | Apache Artemis, Apache Artemis, Apache ActiveMQ Artemis, Apache ActiveMQ Artemis: Pre-auth | |
| CVE-2026-75880 | Apache Artemis, Apache ActiveMQ Artemis: Message selector wildcard handling could lead to |
No comments yet