天下漏洞,尽知其名
HIGH 重点关注

CVE-2026-103413 Apache Camel Karavan 输入验证不当漏洞

影响认证用户可部署特权容器,可能接管集群节点

AI 研判

Apache Camel Karavan 在启动部署时,会解析项目中的 kubernetes.yaml 并将其中所有资源直接应用到集群,未限制资源类型、未拒绝安全敏感的 Pod 配置,也未固定目标命名空间。任意角色的已认证用户均可借此让 Karavan 以其服务账号权限应用任意 Kubernetes 资源。

影响范围

Apache Camel Karavan

Apache Camel Karavan 4.0.0 至 4.22.1 之前的版本。

漏洞详情

漏洞属于输入验证不当(CWE-20)。成因是部署流程对用户提供的 kubernetes.yaml 缺乏校验与白名单限制,导致可提交 hostNetwork、hostPID、hostIPC、hostPath 卷、host 端口、特权容器、权限提升或额外 capability 等危险配置。攻击者只需具备任意角色的登录凭据即可利用。

利用条件与风险

利用前提是攻击者拥有 Karavan 的已认证账号(任意角色)。实战中可借助其服务账号权限在集群内创建特权 Pod,进而逃逸容器、访问宿主机资源,风险较高。

修复建议

官方建议升级至 4.22.1 版本以修复该问题;临时缓解措施暂无公开信息,可考虑限制 Karavan 服务账号权限并限制可访问用户范围。

原始情报

Improper input validation vulnerability in Apache Camel Karavan.

When a deployment was started, Karavan unmarshalled a project’s `kubernetes.yaml` and applied every resource it contained to the cluster without restricting the resource kinds, without rejecting security-sensitive pod options, and without pinning the target namespace. An authenticated user of any role could therefore have Karavan apply arbitrary Kubernetes resources within the reach of its service account, including pods requesting hostNetwork, hostPID, hostIPC, hostPath volumes, host ports, privileged containers, privilege escalation or added capabilities.

This issue affects Apache Camel Karavan: from 4.0.0 before 4.22.1.

Users are recommended to upgrade to version 4.22.1, which fixes the issue.