GHSA-qpxm-689r-3849
Dashboard / Vulnerabilities / GHSA-qpxm-689r-3849
Summary: Apache Camel data exposure vulnerability
Details: Exposure of sensitive data by by crafting a malicious EventFactory and providing a custom ExchangeCreatedEvent that exposes sensitive data. Vulnerability in Apache Camel. This issue affects Apache Camel: from 3.0.0 through 3.21.3, from 3.22.X through 3.22.0, from 4.0.X through 4.0.3, from 4.X through 4.3.0. Users are recommended to upgrade to version 3.21.4, 3.22.1, 4.0.4 or 4.4.0, which fixes the issue.
References: https://nvd.nist.gov/vuln/detail/CVE-2024-22371, https://camel.apache.org/security/CVE-2024-22371.html, https://github.com/apache/camel, https://issues.apache.org/jira/browse/CAMEL-20305
Affected packages
Package
Name: org.apache.camel:camel-core
Purl: pkg:maven/org.apache.camel/camel-core
Affected ranges
Type: ECOSYSTEM
Events:
