CVE-2024-22371

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
26/02/2024
Last modified:
25/04/2025

Description

Exposure of sensitive data by by crafting a malicious EventFactory and providing a custom ExchangeCreatedEvent that exposes sensitive data. Vulnerability in Apache Camel.This issue affects Apache Camel: from 3.21.X through 3.21.3, from 3.22.X through 3.22.0, from 4.0.X through 4.0.3, from 4.X through 4.3.0.<br /> <br /> Users are recommended to upgrade to version 3.21.4, 3.22.1, 4.0.4 or 4.4.0, which fixes the issue.<br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:camel:*:*:*:*:*:*:*:* 3.0.0 (including) 3.21.4 (excluding)
cpe:2.3:a:apache:camel:*:-:*:*:*:*:*:* 4.0.0 (including) 4.0.4 (excluding)
cpe:2.3:a:apache:camel:*:*:*:*:*:*:*:* 4.1.0 (including) 4.4.0 (excluding)
cpe:2.3:a:apache:camel:3.22.0:*:*:*:*:*:*:*