Apache Camel data exposure vulnerability
Low severity
GitHub Reviewed
Published
Feb 26, 2024
to the GitHub Advisory Database
•
Updated Oct 31, 2024
Package
Affected versions
= 3.22.0
>= 4.0.0, < 4.0.4
>= 4.1.0, < 4.4.0
>= 3.0.0, < 3.21.4
Patched versions
3.22.1
4.0.4
4.4.0
3.21.4
Description
Published by the National Vulnerability Database
Feb 26, 2024
Published to the GitHub Advisory Database
Feb 26, 2024
Reviewed
Feb 26, 2024
Last updated
Oct 31, 2024
Exposure of sensitive data by by crafting a malicious EventFactory and providing a custom ExchangeCreatedEvent that exposes sensitive data. Vulnerability in Apache Camel. This issue affects Apache Camel: from 3.0.0 through 3.21.3, from 3.22.X through 3.22.0, from 4.0.X through 4.0.3, from 4.X through 4.3.0.
Users are recommended to upgrade to version 3.21.4, 3.22.1, 4.0.4 or 4.4.0, which fixes the issue.
References