Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qpxm-689r-3849

Опубликовано: 26 фев. 2024
Источник: github
Github: Прошло ревью
CVSS3: 2.9

Описание

Apache Camel data exposure vulnerability

Exposure of sensitive data by by crafting a malicious EventFactory and providing a custom ExchangeCreatedEvent that exposes sensitive data. Vulnerability in Apache Camel. This issue affects Apache Camel: from 3.0.0 through 3.21.3, from 3.22.X through 3.22.0, from 4.0.X through 4.0.3, from 4.X through 4.3.0.

Users are recommended to upgrade to version 3.21.4, 3.22.1, 4.0.4 or 4.4.0, which fixes the issue.

Пакеты

Наименование

org.apache.camel:camel-core

maven
Затронутые версииВерсия исправления

>= 3.0.0, < 3.21.4

3.21.4

Наименование

org.apache.camel:camel-core

maven
Затронутые версииВерсия исправления

= 3.22.0

3.22.1

Наименование

org.apache.camel:camel-core

maven
Затронутые версииВерсия исправления

>= 4.0.0, < 4.0.4

4.0.4

Наименование

org.apache.camel:camel-core

maven
Затронутые версииВерсия исправления

>= 4.1.0, < 4.4.0

4.4.0

EPSS

Процентиль: 68%
0.00581
Низкий

2.9 Low

CVSS3

Дефекты

CWE-200
CWE-922

Связанные уязвимости

CVSS3: 2.9
redhat
почти 2 года назад

Exposure of sensitive data by by crafting a malicious EventFactory and providing a custom ExchangeCreatedEvent that exposes sensitive data. Vulnerability in Apache Camel.This issue affects Apache Camel: from 3.21.X through 3.21.3, from 3.22.X through 3.22.0, from 4.0.X through 4.0.3, from 4.X through 4.3.0. Users are recommended to upgrade to version 3.21.4, 3.22.1, 4.0.4 or 4.4.0, which fixes the issue.

CVSS3: 2.9
nvd
почти 2 года назад

Exposure of sensitive data by by crafting a malicious EventFactory and providing a custom ExchangeCreatedEvent that exposes sensitive data. Vulnerability in Apache Camel.This issue affects Apache Camel: from 3.21.X through 3.21.3, from 3.22.X through 3.22.0, from 4.0.X through 4.0.3, from 4.X through 4.3.0. Users are recommended to upgrade to version 3.21.4, 3.22.1, 4.0.4 or 4.4.0, which fixes the issue.

EPSS

Процентиль: 68%
0.00581
Низкий

2.9 Low

CVSS3

Дефекты

CWE-200
CWE-922