This is an automated email from the ASF dual-hosted git repository.
squakez pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/camel-website.git
The following commit(s) were added to refs/heads/main by this push:
new 64380a26 chore: CK security advisors
64380a26 is described below
commit 64380a26131dc398b0bd7408782e20f0518ef593
Author: Pasquale Congiusti <[email protected]>
AuthorDate: Tue Sep 8 14:21:11 2026 +0200
chore: CK security advisors
---
content/security/CVE-2026-80351.md | 17 ++++++++++++++++
content/security/CVE-2026-80351.txt.asc | 36 +++++++++++++++++++++++++++++++++
content/security/CVE-2026-80352.md | 17 ++++++++++++++++
content/security/CVE-2026-80352.txt.asc | 36 +++++++++++++++++++++++++++++++++
content/security/CVE-2026-80354.md | 17 ++++++++++++++++
content/security/CVE-2026-80354.txt.asc | 36 +++++++++++++++++++++++++++++++++
6 files changed, 159 insertions(+)
diff --git a/content/security/CVE-2026-80351.md
b/content/security/CVE-2026-80351.md
new file mode 100644
index 00000000..6b70354b
--- /dev/null
+++ b/content/security/CVE-2026-80351.md
@@ -0,0 +1,17 @@
+---
+title: "Apache Camel Security Advisory - CVE-2026-80351"
+date: 2026-09-08T11:00:00+02:00
+url: /security/CVE-2026-80351.html
+draft: false
+type: security-advisory
+cve: CVE-2026-80351
+severity: CRITICAL
+summary: "Camel K Tenant repositories reach Maven execution inside operator
pod"
+description: "Improper neutralization of directives in dynamically evaluated
code ('eval injection') vulnerability in Apache Camel K. An improper
neutralization of directives in dynamically evaluated Maven configuration
allows tenant-controlled repository content to influence code execution within
the operator pod, potentially enabling tenants to execute arbitrary code with
the privileges of the operator. This issue affects Apache Camel K: from 2.0.0
before 2.9.3, from 2.10.1 before 2.10 [...]
+mitigation: "Users are recommended to upgrade to version 2.11.0 (or 2.10.2 or
2.9.3), which fixes the issue."
+credit: "This issue was discovered by internal analysis"
+affected: "This issue affects Apache Camel K: from 2.0.0 before 2.9.3, from
2.10.0 before 2.10.2"
+fixed: 2.9.3, 2.10.2 and 2.11.0
+---
+
+The pull requests https://github.com/apache/camel-k/pull/6786 (2.11.x),
https://github.com/apache/camel-k/commit/42b4573a779c4202a205a088e42c781cea3e4ed4
(2.10.x) and
https://github.com/apache/camel-k/commit/954ff98054a28e3369712ecc8522811a70afa802
(2.9.x) refer to the commits that resolved the issue, and have more details.
diff --git a/content/security/CVE-2026-80351.txt.asc
b/content/security/CVE-2026-80351.txt.asc
new file mode 100644
index 00000000..bc2bee91
--- /dev/null
+++ b/content/security/CVE-2026-80351.txt.asc
@@ -0,0 +1,36 @@
+-----BEGIN PGP SIGNED MESSAGE-----
+Hash: SHA512
+
+- ---
+title: "Apache Camel Security Advisory - CVE-2026-80351"
+date: 2026-09-08T11:00:00+02:00
+url: /security/CVE-2026-80351.html
+draft: false
+type: security-advisory
+cve: CVE-2026-80351
+severity: CRITICAL
+summary: "Camel K Tenant repositories reach Maven execution inside operator
pod"
+description: "Improper neutralization of directives in dynamically evaluated
code ('eval injection') vulnerability in Apache Camel K. An improper
neutralization of directives in dynamically evaluated Maven configuration
allows tenant-controlled repository content to influence code execution within
the operator pod, potentially enabling tenants to execute arbitrary code with
the privileges of the operator. This issue affects Apache Camel K: from 2.0.0
before 2.9.3, from 2.10.1 before 2.10 [...]
+mitigation: "Users are recommended to upgrade to version 2.11.0 (or 2.10.2 or
2.9.3), which fixes the issue."
+credit: "This issue was discovered by internal analysis"
+affected: "This issue affects Apache Camel K: from 2.0.0 before 2.9.3, from
2.10.0 before 2.10.2"
+fixed: 2.9.3, 2.10.2 and 2.11.0
+- ---
+
+The pull requests https://github.com/apache/camel-k/pull/6786 (2.11.x),
https://github.com/apache/camel-k/commit/42b4573a779c4202a205a088e42c781cea3e4ed4
(2.10.x) and
https://github.com/apache/camel-k/commit/954ff98054a28e3369712ecc8522811a70afa802
(2.9.x) refer to the commits that resolved the issue, and have more details.
+-----BEGIN PGP SIGNATURE-----
+
+iQIzBAEBCgAdFiEEDV4jKJJJXejlQHXMrtxqiqrKh1YFAmqf0akACgkQrtxqiqrK
+h1akiw//ZckJzq8iyF7fEGbSZYVrZX1OtW4WpG205LyIEmAa8tfXCAeI3a380+fL
+5zIGHXhia20rNB3MMW7Ut4Zg1LQgebPG/jdwkYtWQwzktOogJmsDZWB7CYcowi/i
+EFMCV8H09VqIXFxGcB93F+qEQTAiLVLG3p9TToMpK6B6+YKS9d2Uc2t+7Glfxd1c
+9ciSaGsv+vbiqLECbCH6fpcCTDbA0pH+KsBwhySJoT2weZ1t+Huta3n6NXHlZDfS
+cy+2om5awRByRl1qnc+4kk9WyBpvVr8hJBuRzpm+q2woCzWoiX72ns/674MCzPHg
+cPRzAsZeMXrDKISCev+L83F+8EaciEF6KBj8/limXz7nKqULrfQ1PQT0HPBdysJn
+4ee3iYemRrd2abfzovqARO1YGFjKe/4nwepaezvtlL6eDEj4O9mkW7YjktEbo0IR
+6tEjhkVkrhrmJCF9t1mqhkIbZD2A3PACrogVBeekmk0uY8+9iEiW4fVFjvDb2rkT
+7eKg7E1ypmNRPvC2GGou1R4GPQpISTZ/6W1MOh2IXaKvQ5VaosewJIJAc/deJa5J
+0WyL1DLSHbSootpY2n12WiVcR2gZGw8S+fhDHJYBzT7H3Li351zEH0a65egwAFWX
+doYEfmuQTWbLJPiQDcu4rs00h2wWrvyKOpL6Iiu6CEFr6+E923Q=
+=sGkD
+-----END PGP SIGNATURE-----
diff --git a/content/security/CVE-2026-80352.md
b/content/security/CVE-2026-80352.md
new file mode 100644
index 00000000..b653c3a4
--- /dev/null
+++ b/content/security/CVE-2026-80352.md
@@ -0,0 +1,17 @@
+---
+title: "Apache Camel Security Advisory - CVE-2026-80352"
+date: 2026-09-08T11:00:00+02:00
+url: /security/CVE-2026-80352.html
+draft: false
+type: security-advisory
+cve: CVE-2026-80352
+severity: CRITICAL
+summary: "Camel K Master trait serviceAccountName YAML injection lets CR
author apply arbitrary objects"
+description: "Improper Control of Generation of Code ('Code Injection')
vulnerability in Apache Camel K. A YAML injection vulnerability in custom
resource configuration allows an authorized CR author to inject arbitrary
Kubernetes objects, potentially enabling unauthorized resource creation with
the privileges of the operator. This issue affects Apache Camel K: from 2.0.0
before 2.9.3, from 2.10.1 before 2.10.2. Users are recommended to upgrade to
version 2.9.3, 2.10.2 or 2.11.0, which f [...]
+mitigation: "Users are recommended to upgrade to version 2.11.0 (or 2.10.2 or
2.9.3), which fixes the issue."
+credit: "This issue was discovered by internal analysis"
+affected: "This issue affects Apache Camel K: from 2.0.0 before 2.9.3, from
2.10.0 before 2.10.2"
+fixed: 2.9.3, 2.10.2 and 2.11.0
+---
+
+The pull requests https://github.com/apache/camel-k/pull/6785 (2.11.x),
https://github.com/apache/camel-k/commit/021f4baa7678e6244077ae7fb0edb41a3543757c
(2.10.x) and
https://github.com/apache/camel-k/commit/f0659822418eb3c0ab2b2090a797d7f0b8275763
(2.9.x) refer to the commits that resolved the issue, and have more details.
diff --git a/content/security/CVE-2026-80352.txt.asc
b/content/security/CVE-2026-80352.txt.asc
new file mode 100644
index 00000000..4d2828e0
--- /dev/null
+++ b/content/security/CVE-2026-80352.txt.asc
@@ -0,0 +1,36 @@
+-----BEGIN PGP SIGNED MESSAGE-----
+Hash: SHA512
+
+- ---
+title: "Apache Camel Security Advisory - CVE-2026-80352"
+date: 2026-09-08T11:00:00+02:00
+url: /security/CVE-2026-80352.html
+draft: false
+type: security-advisory
+cve: CVE-2026-80352
+severity: CRITICAL
+summary: "Camel K Master trait serviceAccountName YAML injection lets CR
author apply arbitrary objects"
+description: "Improper Control of Generation of Code ('Code Injection')
vulnerability in Apache Camel K. A YAML injection vulnerability in custom
resource configuration allows an authorized CR author to inject arbitrary
Kubernetes objects, potentially enabling unauthorized resource creation with
the privileges of the operator. This issue affects Apache Camel K: from 2.0.0
before 2.9.3, from 2.10.1 before 2.10.2. Users are recommended to upgrade to
version 2.9.3, 2.10.2 or 2.11.0, which f [...]
+mitigation: "Users are recommended to upgrade to version 2.11.0 (or 2.10.2 or
2.9.3), which fixes the issue."
+credit: "This issue was discovered by internal analysis"
+affected: "This issue affects Apache Camel K: from 2.0.0 before 2.9.3, from
2.10.0 before 2.10.2"
+fixed: 2.9.3, 2.10.2 and 2.11.0
+- ---
+
+The pull requests https://github.com/apache/camel-k/pull/6785 (2.11.x),
https://github.com/apache/camel-k/commit/021f4baa7678e6244077ae7fb0edb41a3543757c
(2.10.x) and
https://github.com/apache/camel-k/commit/f0659822418eb3c0ab2b2090a797d7f0b8275763
(2.9.x) refer to the commits that resolved the issue, and have more details.
+-----BEGIN PGP SIGNATURE-----
+
+iQIzBAEBCgAdFiEEDV4jKJJJXejlQHXMrtxqiqrKh1YFAmqf/L4ACgkQrtxqiqrK
+h1ZyGA/8Df6FWCClQdoNuMD97qRYP0LFG6vIttAi7q4NboZ1Gy8PBo+d+q9HPern
+TJ3xSt6OGJ2CZy0MkmqAUtFis+wuRO6eiNJx7be+9MMUVgfZiBnFebgWCPgf/dvi
+OAM/TPXyXOhYjwaa5H2U0pKxWSk/c+gVwDpTzj1SAUfuiwEr+WBvXiYZlA2FLb+I
+FIp6IbygA3eb3mgrFrs8cJRnFCJpE1p1gZmK5jxXZ/jFlNkxXNjDcQuBtYy6zZHr
+1qEVC3M4DMtrJeEJdIF/tzX+R+ObRufdNRWKrrM9Utj+leJYe9dg1kApQub+m3vc
+ivkqWjMZ+DZw2Set795a43Fy/Zos6ixM+lyJ3fnkhZMTL25kLkqg+28zjakCBRcR
+O4bwzcW2msYYNLJtP+pjg1CEJI8obnFB7gy24xYVAkphNGZOy7z1MIajwUbpZ+QZ
+MEWNlZ0ZTFczMWaijGCda0MkEP8GD0iWjbMZlwRwJwksHecD2EuA1og7iRdCqHSf
+0UVtD+hNgg7j4RjIlGi/C1niOHaforzLDeyLdaJHpvDTMb9LoEKgBsL7j3pI9ezP
++tWDQ6PHos1G8KrYj4EJ/NAR5PnzFvzZdgRzl89X9YSKZFi0cB9OuF1C5N2L7gDb
+fe2DwhuqS0+64rbZjiUxbWcsj+DNvVkypRofwBZWPI0Vobx/WRY=
+=LAkH
+-----END PGP SIGNATURE-----
diff --git a/content/security/CVE-2026-80354.md
b/content/security/CVE-2026-80354.md
new file mode 100644
index 00000000..bbe993a9
--- /dev/null
+++ b/content/security/CVE-2026-80354.md
@@ -0,0 +1,17 @@
+---
+title: "Apache Camel Security Advisory - CVE-2026-80354"
+date: 2026-09-08T11:00:00+02:00
+url: /security/CVE-2026-80354.html
+draft: false
+type: security-advisory
+cve: CVE-2026-80354
+severity: MODERATE
+summary: "Camel K Builder trait mavenProfiles ValueSources resolve
tenant-named secrets in operator namespace"
+description: "Authorization bypass through User-Controlled key vulnerability
in Apache Camel K. An authorization vulnerability in custom resource resolution
allows a tenant to reference secrets by name in the operator namespace,
potentially exposing secrets belonging to other tenants or operator components.
This issue affects Apache Camel K: from 2.0.0 before 2.9.3, from 2.10.1 before
2.10.2. Users are recommended to upgrade to version 2.9.3, 2.10.2 or 2.11.0,
which fixes the issue."
+mitigation: "Users are recommended to upgrade to version 2.11.0 (or 2.10.2 or
2.9.3), which fixes the issue."
+credit: "This issue was discovered by internal analysis"
+affected: "This issue affects Apache Camel K: from 2.0.0 before 2.9.3, from
2.10.0 before 2.10.2"
+fixed: 2.9.3, 2.10.2 and 2.11.0
+---
+
+The pull requests https://github.com/apache/camel-k/pull/6784 (2.11.x),
https://github.com/apache/camel-k/commit/047e359168c473d88cd3f3f848904255451d284f
(2.10.x) and
https://github.com/apache/camel-k/commit/46b98e7a46575fcbe3e66192d842092047259886
(2.9.x) refer to the commits that resolved the issue, and have more details.
diff --git a/content/security/CVE-2026-80354.txt.asc
b/content/security/CVE-2026-80354.txt.asc
new file mode 100644
index 00000000..ba775ed0
--- /dev/null
+++ b/content/security/CVE-2026-80354.txt.asc
@@ -0,0 +1,36 @@
+-----BEGIN PGP SIGNED MESSAGE-----
+Hash: SHA512
+
+- ---
+title: "Apache Camel Security Advisory - CVE-2026-80354"
+date: 2026-09-08T11:00:00+02:00
+url: /security/CVE-2026-80354.html
+draft: false
+type: security-advisory
+cve: CVE-2026-80354
+severity: MODERATE
+summary: "Camel K Builder trait mavenProfiles ValueSources resolve
tenant-named secrets in operator namespace"
+description: "Authorization bypass through User-Controlled key vulnerability
in Apache Camel K. An authorization vulnerability in custom resource resolution
allows a tenant to reference secrets by name in the operator namespace,
potentially exposing secrets belonging to other tenants or operator components.
This issue affects Apache Camel K: from 2.0.0 before 2.9.3, from 2.10.1 before
2.10.2. Users are recommended to upgrade to version 2.9.3, 2.10.2 or 2.11.0,
which fixes the issue."
+mitigation: "Users are recommended to upgrade to version 2.11.0 (or 2.10.2 or
2.9.3), which fixes the issue."
+credit: "This issue was discovered by internal analysis"
+affected: "This issue affects Apache Camel K: from 2.0.0 before 2.9.3, from
2.10.0 before 2.10.2"
+fixed: 2.9.3, 2.10.2 and 2.11.0
+- ---
+
+The pull requests https://github.com/apache/camel-k/pull/6784 (2.11.x),
https://github.com/apache/camel-k/commit/047e359168c473d88cd3f3f848904255451d284f
(2.10.x) and
https://github.com/apache/camel-k/commit/46b98e7a46575fcbe3e66192d842092047259886
(2.9.x) refer to the commits that resolved the issue, and have more details.
+-----BEGIN PGP SIGNATURE-----
+
+iQIzBAEBCgAdFiEEDV4jKJJJXejlQHXMrtxqiqrKh1YFAmqf/ggACgkQrtxqiqrK
+h1Yl9g//X2wDb8D2MCAbMmP/Py9QMCLlF7zUUSc7+zgmh55GXUVAID3/weOAvZER
+OCt1fRCGcIMiDqC+kdTtB2XH4TzlhFv3V6zPUzURJ+BK2K9wuzHP3Sm9x6DHGF1u
+PJ63e1x4cH3Z0GqXeT2hGskqopzo89N19Utq7Vflnb05ll99wkOyOEh3Ca8Ih9Ex
+ApuwTc3nu0SVIUcfA5x6lbzSVLxAOuROPRNMNbbU178GV77cek9lR3fJY6tydFz7
+NpvyeS3aYrd1YTsR/zYRYOfU2uMQkb4du2IdjSzK7JwD+JPddpkIWWewHszaTP7T
+5lZ6Wv/tD6xGnaxKfvsEEfgrRYSmc9OQnzIw6KyCxr7Pd/LTOxK58SZHhFk8fBi5
++yRVlVAnKZ3CFTlpXC8CoSFXvTf4pa4/cD3VIEfYYsnQfc8Yr9DnbYTGvARiiqrY
+bITlWF7h9lSMR0cXCAgCzgU2tsdJiUt86AQXlLUYgs3qptCm02bBBftjTg3vEUHl
+pJVCWIz4FRypv7SAWrLgLjHlAHOtZv7vWYQ8vKM7QhaTpe1ZIokvsHrGfKccsU0S
+wZxtMYkeWfeI1fNKz/cLnpITwC/7tqlgkrjft+vsLqqFKc358CXS9c3ue0ueYd7Z
+6QhdSr2WF2rCcwB3fKIuezzo4pxO01QBzXOHommk1jDPI0hECj0=
+=hi70
+-----END PGP SIGNATURE-----