This is an automated email from the ASF dual-hosted git repository.

squakez pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/camel-website.git


The following commit(s) were added to refs/heads/main by this push:
     new 64380a26 chore: CK security advisors
64380a26 is described below

commit 64380a26131dc398b0bd7408782e20f0518ef593
Author: Pasquale Congiusti <[email protected]>
AuthorDate: Tue Sep 8 14:21:11 2026 +0200

    chore: CK security advisors
---
 content/security/CVE-2026-80351.md      | 17 ++++++++++++++++
 content/security/CVE-2026-80351.txt.asc | 36 +++++++++++++++++++++++++++++++++
 content/security/CVE-2026-80352.md      | 17 ++++++++++++++++
 content/security/CVE-2026-80352.txt.asc | 36 +++++++++++++++++++++++++++++++++
 content/security/CVE-2026-80354.md      | 17 ++++++++++++++++
 content/security/CVE-2026-80354.txt.asc | 36 +++++++++++++++++++++++++++++++++
 6 files changed, 159 insertions(+)

diff --git a/content/security/CVE-2026-80351.md 
b/content/security/CVE-2026-80351.md
new file mode 100644
index 00000000..6b70354b
--- /dev/null
+++ b/content/security/CVE-2026-80351.md
@@ -0,0 +1,17 @@
+---
+title: "Apache Camel Security Advisory - CVE-2026-80351"
+date: 2026-09-08T11:00:00+02:00
+url: /security/CVE-2026-80351.html
+draft: false
+type: security-advisory
+cve: CVE-2026-80351
+severity: CRITICAL
+summary: "Camel K Tenant repositories reach Maven execution inside operator 
pod"
+description: "Improper neutralization of directives in dynamically evaluated 
code ('eval injection') vulnerability in Apache Camel K. An improper 
neutralization of directives in dynamically evaluated Maven configuration 
allows tenant-controlled repository content to influence code execution within 
the operator pod, potentially enabling tenants to execute arbitrary code with 
the privileges of the operator. This issue affects Apache Camel K: from 2.0.0 
before 2.9.3, from 2.10.1 before 2.10 [...]
+mitigation: "Users are recommended to upgrade to version 2.11.0 (or 2.10.2 or 
2.9.3), which fixes the issue."
+credit: "This issue was discovered by internal analysis"
+affected: "This issue affects Apache Camel K: from 2.0.0 before 2.9.3, from 
2.10.0 before 2.10.2"
+fixed: 2.9.3, 2.10.2 and 2.11.0
+---
+
+The pull requests https://github.com/apache/camel-k/pull/6786 (2.11.x), 
https://github.com/apache/camel-k/commit/42b4573a779c4202a205a088e42c781cea3e4ed4
 (2.10.x) and 
https://github.com/apache/camel-k/commit/954ff98054a28e3369712ecc8522811a70afa802
 (2.9.x) refer to the commits that resolved the issue, and have more details.
diff --git a/content/security/CVE-2026-80351.txt.asc 
b/content/security/CVE-2026-80351.txt.asc
new file mode 100644
index 00000000..bc2bee91
--- /dev/null
+++ b/content/security/CVE-2026-80351.txt.asc
@@ -0,0 +1,36 @@
+-----BEGIN PGP SIGNED MESSAGE-----
+Hash: SHA512
+
+- ---
+title: "Apache Camel Security Advisory - CVE-2026-80351"
+date: 2026-09-08T11:00:00+02:00
+url: /security/CVE-2026-80351.html
+draft: false
+type: security-advisory
+cve: CVE-2026-80351
+severity: CRITICAL
+summary: "Camel K Tenant repositories reach Maven execution inside operator 
pod"
+description: "Improper neutralization of directives in dynamically evaluated 
code ('eval injection') vulnerability in Apache Camel K. An improper 
neutralization of directives in dynamically evaluated Maven configuration 
allows tenant-controlled repository content to influence code execution within 
the operator pod, potentially enabling tenants to execute arbitrary code with 
the privileges of the operator. This issue affects Apache Camel K: from 2.0.0 
before 2.9.3, from 2.10.1 before 2.10 [...]
+mitigation: "Users are recommended to upgrade to version 2.11.0 (or 2.10.2 or 
2.9.3), which fixes the issue."
+credit: "This issue was discovered by internal analysis"
+affected: "This issue affects Apache Camel K: from 2.0.0 before 2.9.3, from 
2.10.0 before 2.10.2"
+fixed: 2.9.3, 2.10.2 and 2.11.0
+- ---
+
+The pull requests https://github.com/apache/camel-k/pull/6786 (2.11.x), 
https://github.com/apache/camel-k/commit/42b4573a779c4202a205a088e42c781cea3e4ed4
 (2.10.x) and 
https://github.com/apache/camel-k/commit/954ff98054a28e3369712ecc8522811a70afa802
 (2.9.x) refer to the commits that resolved the issue, and have more details.
+-----BEGIN PGP SIGNATURE-----
+
+iQIzBAEBCgAdFiEEDV4jKJJJXejlQHXMrtxqiqrKh1YFAmqf0akACgkQrtxqiqrK
+h1akiw//ZckJzq8iyF7fEGbSZYVrZX1OtW4WpG205LyIEmAa8tfXCAeI3a380+fL
+5zIGHXhia20rNB3MMW7Ut4Zg1LQgebPG/jdwkYtWQwzktOogJmsDZWB7CYcowi/i
+EFMCV8H09VqIXFxGcB93F+qEQTAiLVLG3p9TToMpK6B6+YKS9d2Uc2t+7Glfxd1c
+9ciSaGsv+vbiqLECbCH6fpcCTDbA0pH+KsBwhySJoT2weZ1t+Huta3n6NXHlZDfS
+cy+2om5awRByRl1qnc+4kk9WyBpvVr8hJBuRzpm+q2woCzWoiX72ns/674MCzPHg
+cPRzAsZeMXrDKISCev+L83F+8EaciEF6KBj8/limXz7nKqULrfQ1PQT0HPBdysJn
+4ee3iYemRrd2abfzovqARO1YGFjKe/4nwepaezvtlL6eDEj4O9mkW7YjktEbo0IR
+6tEjhkVkrhrmJCF9t1mqhkIbZD2A3PACrogVBeekmk0uY8+9iEiW4fVFjvDb2rkT
+7eKg7E1ypmNRPvC2GGou1R4GPQpISTZ/6W1MOh2IXaKvQ5VaosewJIJAc/deJa5J
+0WyL1DLSHbSootpY2n12WiVcR2gZGw8S+fhDHJYBzT7H3Li351zEH0a65egwAFWX
+doYEfmuQTWbLJPiQDcu4rs00h2wWrvyKOpL6Iiu6CEFr6+E923Q=
+=sGkD
+-----END PGP SIGNATURE-----
diff --git a/content/security/CVE-2026-80352.md 
b/content/security/CVE-2026-80352.md
new file mode 100644
index 00000000..b653c3a4
--- /dev/null
+++ b/content/security/CVE-2026-80352.md
@@ -0,0 +1,17 @@
+---
+title: "Apache Camel Security Advisory - CVE-2026-80352"
+date: 2026-09-08T11:00:00+02:00
+url: /security/CVE-2026-80352.html
+draft: false
+type: security-advisory
+cve: CVE-2026-80352
+severity: CRITICAL
+summary: "Camel K Master trait serviceAccountName YAML injection lets CR 
author apply arbitrary objects"
+description: "Improper Control of Generation of Code ('Code Injection') 
vulnerability in Apache Camel K. A YAML injection vulnerability in custom 
resource configuration allows an authorized CR author to inject arbitrary 
Kubernetes objects, potentially enabling unauthorized resource creation with 
the privileges of the operator. This issue affects Apache Camel K: from 2.0.0 
before 2.9.3, from 2.10.1 before 2.10.2. Users are recommended to upgrade to 
version 2.9.3, 2.10.2 or 2.11.0, which f [...]
+mitigation: "Users are recommended to upgrade to version 2.11.0 (or 2.10.2 or 
2.9.3), which fixes the issue."
+credit: "This issue was discovered by internal analysis"
+affected: "This issue affects Apache Camel K: from 2.0.0 before 2.9.3, from 
2.10.0 before 2.10.2"
+fixed: 2.9.3, 2.10.2 and 2.11.0
+---
+
+The pull requests https://github.com/apache/camel-k/pull/6785 (2.11.x), 
https://github.com/apache/camel-k/commit/021f4baa7678e6244077ae7fb0edb41a3543757c
 (2.10.x) and 
https://github.com/apache/camel-k/commit/f0659822418eb3c0ab2b2090a797d7f0b8275763
 (2.9.x) refer to the commits that resolved the issue, and have more details.
diff --git a/content/security/CVE-2026-80352.txt.asc 
b/content/security/CVE-2026-80352.txt.asc
new file mode 100644
index 00000000..4d2828e0
--- /dev/null
+++ b/content/security/CVE-2026-80352.txt.asc
@@ -0,0 +1,36 @@
+-----BEGIN PGP SIGNED MESSAGE-----
+Hash: SHA512
+
+- ---
+title: "Apache Camel Security Advisory - CVE-2026-80352"
+date: 2026-09-08T11:00:00+02:00
+url: /security/CVE-2026-80352.html
+draft: false
+type: security-advisory
+cve: CVE-2026-80352
+severity: CRITICAL
+summary: "Camel K Master trait serviceAccountName YAML injection lets CR 
author apply arbitrary objects"
+description: "Improper Control of Generation of Code ('Code Injection') 
vulnerability in Apache Camel K. A YAML injection vulnerability in custom 
resource configuration allows an authorized CR author to inject arbitrary 
Kubernetes objects, potentially enabling unauthorized resource creation with 
the privileges of the operator. This issue affects Apache Camel K: from 2.0.0 
before 2.9.3, from 2.10.1 before 2.10.2. Users are recommended to upgrade to 
version 2.9.3, 2.10.2 or 2.11.0, which f [...]
+mitigation: "Users are recommended to upgrade to version 2.11.0 (or 2.10.2 or 
2.9.3), which fixes the issue."
+credit: "This issue was discovered by internal analysis"
+affected: "This issue affects Apache Camel K: from 2.0.0 before 2.9.3, from 
2.10.0 before 2.10.2"
+fixed: 2.9.3, 2.10.2 and 2.11.0
+- ---
+
+The pull requests https://github.com/apache/camel-k/pull/6785 (2.11.x), 
https://github.com/apache/camel-k/commit/021f4baa7678e6244077ae7fb0edb41a3543757c
 (2.10.x) and 
https://github.com/apache/camel-k/commit/f0659822418eb3c0ab2b2090a797d7f0b8275763
 (2.9.x) refer to the commits that resolved the issue, and have more details.
+-----BEGIN PGP SIGNATURE-----
+
+iQIzBAEBCgAdFiEEDV4jKJJJXejlQHXMrtxqiqrKh1YFAmqf/L4ACgkQrtxqiqrK
+h1ZyGA/8Df6FWCClQdoNuMD97qRYP0LFG6vIttAi7q4NboZ1Gy8PBo+d+q9HPern
+TJ3xSt6OGJ2CZy0MkmqAUtFis+wuRO6eiNJx7be+9MMUVgfZiBnFebgWCPgf/dvi
+OAM/TPXyXOhYjwaa5H2U0pKxWSk/c+gVwDpTzj1SAUfuiwEr+WBvXiYZlA2FLb+I
+FIp6IbygA3eb3mgrFrs8cJRnFCJpE1p1gZmK5jxXZ/jFlNkxXNjDcQuBtYy6zZHr
+1qEVC3M4DMtrJeEJdIF/tzX+R+ObRufdNRWKrrM9Utj+leJYe9dg1kApQub+m3vc
+ivkqWjMZ+DZw2Set795a43Fy/Zos6ixM+lyJ3fnkhZMTL25kLkqg+28zjakCBRcR
+O4bwzcW2msYYNLJtP+pjg1CEJI8obnFB7gy24xYVAkphNGZOy7z1MIajwUbpZ+QZ
+MEWNlZ0ZTFczMWaijGCda0MkEP8GD0iWjbMZlwRwJwksHecD2EuA1og7iRdCqHSf
+0UVtD+hNgg7j4RjIlGi/C1niOHaforzLDeyLdaJHpvDTMb9LoEKgBsL7j3pI9ezP
++tWDQ6PHos1G8KrYj4EJ/NAR5PnzFvzZdgRzl89X9YSKZFi0cB9OuF1C5N2L7gDb
+fe2DwhuqS0+64rbZjiUxbWcsj+DNvVkypRofwBZWPI0Vobx/WRY=
+=LAkH
+-----END PGP SIGNATURE-----
diff --git a/content/security/CVE-2026-80354.md 
b/content/security/CVE-2026-80354.md
new file mode 100644
index 00000000..bbe993a9
--- /dev/null
+++ b/content/security/CVE-2026-80354.md
@@ -0,0 +1,17 @@
+---
+title: "Apache Camel Security Advisory - CVE-2026-80354"
+date: 2026-09-08T11:00:00+02:00
+url: /security/CVE-2026-80354.html
+draft: false
+type: security-advisory
+cve: CVE-2026-80354
+severity: MODERATE
+summary: "Camel K Builder trait mavenProfiles ValueSources resolve 
tenant-named secrets in operator namespace"
+description: "Authorization bypass through User-Controlled key vulnerability 
in Apache Camel K. An authorization vulnerability in custom resource resolution 
allows a tenant to reference secrets by name in the operator namespace, 
potentially exposing secrets belonging to other tenants or operator components. 
This issue affects Apache Camel K: from 2.0.0 before 2.9.3, from 2.10.1 before 
2.10.2. Users are recommended to upgrade to version 2.9.3, 2.10.2 or 2.11.0, 
which fixes the issue."
+mitigation: "Users are recommended to upgrade to version 2.11.0 (or 2.10.2 or 
2.9.3), which fixes the issue."
+credit: "This issue was discovered by internal analysis"
+affected: "This issue affects Apache Camel K: from 2.0.0 before 2.9.3, from 
2.10.0 before 2.10.2"
+fixed: 2.9.3, 2.10.2 and 2.11.0
+---
+
+The pull requests https://github.com/apache/camel-k/pull/6784 (2.11.x), 
https://github.com/apache/camel-k/commit/047e359168c473d88cd3f3f848904255451d284f
 (2.10.x) and 
https://github.com/apache/camel-k/commit/46b98e7a46575fcbe3e66192d842092047259886
 (2.9.x) refer to the commits that resolved the issue, and have more details.
diff --git a/content/security/CVE-2026-80354.txt.asc 
b/content/security/CVE-2026-80354.txt.asc
new file mode 100644
index 00000000..ba775ed0
--- /dev/null
+++ b/content/security/CVE-2026-80354.txt.asc
@@ -0,0 +1,36 @@
+-----BEGIN PGP SIGNED MESSAGE-----
+Hash: SHA512
+
+- ---
+title: "Apache Camel Security Advisory - CVE-2026-80354"
+date: 2026-09-08T11:00:00+02:00
+url: /security/CVE-2026-80354.html
+draft: false
+type: security-advisory
+cve: CVE-2026-80354
+severity: MODERATE
+summary: "Camel K Builder trait mavenProfiles ValueSources resolve 
tenant-named secrets in operator namespace"
+description: "Authorization bypass through User-Controlled key vulnerability 
in Apache Camel K. An authorization vulnerability in custom resource resolution 
allows a tenant to reference secrets by name in the operator namespace, 
potentially exposing secrets belonging to other tenants or operator components. 
This issue affects Apache Camel K: from 2.0.0 before 2.9.3, from 2.10.1 before 
2.10.2. Users are recommended to upgrade to version 2.9.3, 2.10.2 or 2.11.0, 
which fixes the issue."
+mitigation: "Users are recommended to upgrade to version 2.11.0 (or 2.10.2 or 
2.9.3), which fixes the issue."
+credit: "This issue was discovered by internal analysis"
+affected: "This issue affects Apache Camel K: from 2.0.0 before 2.9.3, from 
2.10.0 before 2.10.2"
+fixed: 2.9.3, 2.10.2 and 2.11.0
+- ---
+
+The pull requests https://github.com/apache/camel-k/pull/6784 (2.11.x), 
https://github.com/apache/camel-k/commit/047e359168c473d88cd3f3f848904255451d284f
 (2.10.x) and 
https://github.com/apache/camel-k/commit/46b98e7a46575fcbe3e66192d842092047259886
 (2.9.x) refer to the commits that resolved the issue, and have more details.
+-----BEGIN PGP SIGNATURE-----
+
+iQIzBAEBCgAdFiEEDV4jKJJJXejlQHXMrtxqiqrKh1YFAmqf/ggACgkQrtxqiqrK
+h1Yl9g//X2wDb8D2MCAbMmP/Py9QMCLlF7zUUSc7+zgmh55GXUVAID3/weOAvZER
+OCt1fRCGcIMiDqC+kdTtB2XH4TzlhFv3V6zPUzURJ+BK2K9wuzHP3Sm9x6DHGF1u
+PJ63e1x4cH3Z0GqXeT2hGskqopzo89N19Utq7Vflnb05ll99wkOyOEh3Ca8Ih9Ex
+ApuwTc3nu0SVIUcfA5x6lbzSVLxAOuROPRNMNbbU178GV77cek9lR3fJY6tydFz7
+NpvyeS3aYrd1YTsR/zYRYOfU2uMQkb4du2IdjSzK7JwD+JPddpkIWWewHszaTP7T
+5lZ6Wv/tD6xGnaxKfvsEEfgrRYSmc9OQnzIw6KyCxr7Pd/LTOxK58SZHhFk8fBi5
++yRVlVAnKZ3CFTlpXC8CoSFXvTf4pa4/cD3VIEfYYsnQfc8Yr9DnbYTGvARiiqrY
+bITlWF7h9lSMR0cXCAgCzgU2tsdJiUt86AQXlLUYgs3qptCm02bBBftjTg3vEUHl
+pJVCWIz4FRypv7SAWrLgLjHlAHOtZv7vWYQ8vKM7QhaTpe1ZIokvsHrGfKccsU0S
+wZxtMYkeWfeI1fNKz/cLnpITwC/7tqlgkrjft+vsLqqFKc358CXS9c3ue0ueYd7Z
+6QhdSr2WF2rCcwB3fKIuezzo4pxO01QBzXOHommk1jDPI0hECj0=
+=hi70
+-----END PGP SIGNATURE-----

Reply via email to