Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-22371

Опубликовано: 23 фев. 2024
Источник: redhat
CVSS3: 2.9

Описание

Exposure of sensitive data by by crafting a malicious EventFactory and providing a custom ExchangeCreatedEvent that exposes sensitive data. Vulnerability in Apache Camel.This issue affects Apache Camel: from 3.21.X through 3.21.3, from 3.22.X through 3.22.0, from 4.0.X through 4.0.3, from 4.X through 4.3.0. Users are recommended to upgrade to version 3.21.4, 3.22.1, 4.0.4 or 4.4.0, which fixes the issue.

A flaw was found in Apache Camel. This issue may allow an attacker to expose sensitive data by crafting a malicious EventFactory and providing a custom ExchangeCreatedEvent.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Serverlesscamel-coreNot affected
Red Hat build of Apache Camel 4 for Quarkus 3camel-coreAffected
Red Hat build of Apache Camel for Spring Boot 3camel-coreOut of support scope
Red Hat build of Apache Camel for Spring Boot 4camel-coreNot affected
Red Hat build of Apache Camel - HawtIO 4camel-coreWill not fix
Red Hat Build of Keycloakcamel-coreNot affected
Red Hat Fuse 7camel-coreOut of support scope
Red Hat Integration Camel K 1camel-coreFix deferred
Red Hat Integration Camel Quarkus 2camel-coreWill not fix
Red Hat JBoss Data Grid 7camel-coreWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-201
https://bugzilla.redhat.com/show_bug.cgi?id=2266024camel-core: Exposure of sensitive data by crafting a malicious EventFactory

2.9 Low

CVSS3

Связанные уязвимости

CVSS3: 2.9
nvd
почти 2 года назад

Exposure of sensitive data by by crafting a malicious EventFactory and providing a custom ExchangeCreatedEvent that exposes sensitive data. Vulnerability in Apache Camel.This issue affects Apache Camel: from 3.21.X through 3.21.3, from 3.22.X through 3.22.0, from 4.0.X through 4.0.3, from 4.X through 4.3.0. Users are recommended to upgrade to version 3.21.4, 3.22.1, 4.0.4 or 4.4.0, which fixes the issue.

CVSS3: 2.9
github
почти 2 года назад

Apache Camel data exposure vulnerability

2.9 Low

CVSS3