Apache Camel Karavan: project file name path traversal when committing a project to Git
Summary
| CVE | CVE-2026-103412 |
|---|---|
| State | PUBLISHED |
| Assigner | apache |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-10-09 13:17:07 UTC |
| Updated | 2026-10-09 16:33:39 UTC |
| Description | Improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Apache Camel Karavan. A project file name supplied through the project file API was used verbatim as a path segment when the project was written to the working copy for a Git commit, so a name containing `../` sequences caused the file content to be written outside the project directory, to any location writable by the Karavan process. An authenticated user of any role could use this to overwrite application configuration or files on the application classpath and so execute code in the Karavan container. This issue affects Apache Camel Karavan: from 3.18.0 before 4.22.1. Users are recommended to upgrade to version 4.22.1, which fixes the issue. |
Risk And Classification
Primary CVSS: v3.1 8.8 HIGH from [email protected]
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.005150000 probability, percentile 0.421030000 (date 2026-10-10)
Problem Types: CWE-22 | CWE-22 CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 8.8 | HIGH | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | CNA | CVSS | 8.8 | HIGH | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Apache Software Foundation | Apache Camel Karavan | affected 3.18.0 4.22.1 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.openwall.com/lists/oss-security/2026/10/09/16 | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| camel.apache.org/security/CVE-2026-103412.html | [email protected] | camel.apache.org | |
| github.com/apache/camel-karavan/commit/5e4252494817af0cd2697216bd02f3610... | [email protected] | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: CyberLeo (en)
CNA: Marat Gubaidullin (en)
CNA: Andrea Cosentino (en)
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| CNA | 2026-08-28T00:00:00.000Z | Reported to the Apache Security Team and forwarded to the Apache Camel PMC |
| CNA | 2026-08-28T00:00:00.000Z | Fix committed |
| CNA | 2026-09-29T00:00:00.000Z | Apache Camel Karavan 4.22.1 released |
| CNA | 2026-10-07T00:00:00.000Z | Advisory published |
Solutions
CNA: Upgrade to Apache Camel Karavan 4.22.1. Apache Camel Karavan has no maintenance branches, so 4.22.1 is the only release containing the fix.
There are currently no legacy QID mappings associated with this CVE.