天下漏洞,尽知其名
HIGH 重点关注

CVE-2026-103412 Apache Camel Karavan 路径遍历漏洞

影响攻击者可覆盖应用配置或类路径文件,进而执行任意代码

AI 研判

Apache Camel Karavan 在处理项目文件 API 提供的项目文件名时,未对路径进行限制,直接将文件名用作路径片段写入 Git 提交的工作副本。攻击者可通过包含 ../ 序列的文件名将文件内容写入项目目录之外的任意可写位置。该漏洞影响 3.18.0 至 4.22.1 之前的版本。

影响范围

Apache Camel Karavan

Apache Camel Karavan 3.18.0 起至 4.22.1 之前的版本。

漏洞详情

漏洞类型为路径遍历(CWE-22)。成因是项目文件名被原样拼接为路径片段,未做规范化或目录限制校验。任何已认证用户(不限角色)均可利用 ../ 序列将文件写出项目目录,覆盖应用配置或 classpath 上的文件,从而在 Karavan 容器中执行代码。

利用条件与风险

利用需已认证账户,但任意角色均可触发,门槛较低;成功利用可导致容器内代码执行,风险较高。

修复建议

官方建议升级至 4.22.1 版本以修复该问题;暂无公开的临时缓解措施信息。

原始情报

Improper limitation of a pathname to a restricted directory (‘path traversal’) vulnerability in Apache Camel Karavan.

A project file name supplied through the project file API was used verbatim as a path segment when the project was written to the working copy for a Git commit, so a name containing `../` sequences caused the file content to be written outside the project directory, to any location writable by the Karavan process. An authenticated user of any role could use this to overwrite application configuration or files on the application classpath and so execute code in the Karavan container.

This issue affects Apache Camel Karavan: from 3.18.0 before 4.22.1.

Users are recommended to upgrade to version 4.22.1, which fixes the issue.