Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-30177

Опубликовано: 01 апр. 2025
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

Bypass/Injection vulnerability in Apache Camel in Camel-Undertow component under particular conditions. This issue affects Apache Camel: from 4.10.0 before 4.10.3, from 4.8.0 before 4.8.6. Users are recommended to upgrade to version 4.10.3 for 4.10.x LTS and 4.8.6 for 4.8.x LTS. Camel undertow component is vulnerable to Camel message header injection, in particular the custom header filter strategy used by the component only filter the "out" direction, while it doesn't filter the "in" direction. This allows an attacker to include Camel specific headers that for some Camel components can alter the behaviour such as the camel-bean component, or the camel-exec component.

A flaw was found in the Apache Camel Undertow component. This vulnerability allows an attacker to inject Camel-specific headers via the inbound request, which can alter the behavior of certain Camel components such as camel-bean and camel-exec. This issue occurs due to the custom header filter strategy only applying to outgoing messages and not filtering incoming ones.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Apache Camel for Spring Boot 4camel-undertowFix deferred
Red Hat build of Apache Camel for Spring Boot 4camel-undertow-spring-securityFix deferred
Red Hat Fuse 7camel-undertowNot affected
Red Hat Fuse 7camel-undertow-spring-securityNot affected
Red Hat Fuse 7camel-undertow-spring-security-starterNot affected
Red Hat Fuse 7camel-undertow-starterNot affected
Red Hat Integration Camel K 1camel-undertowNot affected
Red Hat Integration Camel K 1camel-undertow-spring-securityNot affected
Red Hat JBoss Enterprise Application Platform 8camel-undertowNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packcamel-undertowNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-164
https://bugzilla.redhat.com/show_bug.cgi?id=2356545org.apache.camel/camel-undertow: Apache Camel: Camel-Undertow Message Header Injection via Improper Filtering

EPSS

Процентиль: 30%
0.00112
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
6 месяцев назад

Bypass/Injection vulnerability in Apache Camel in Camel-Undertow component under particular conditions. This issue affects Apache Camel: from 4.10.0 before 4.10.3, from 4.8.0 before 4.8.6. Users are recommended to upgrade to version 4.10.3 for 4.10.x LTS and 4.8.6 for 4.8.x LTS. Camel undertow component is vulnerable to Camel message header injection, in particular the custom header filter strategy used by the component only filter the "out" direction, while it doesn't filter the "in" direction. This allows an attacker to include Camel specific headers that for some Camel components can alter the behaviour such as the camel-bean component, or the camel-exec component.

CVSS3: 6.5
github
6 месяцев назад

Apache Camel Missing Header Out Filter Leads to Potential Bypass/Injection Vulnerability

CVSS3: 6.5
fstec
6 месяцев назад

Уязвимость компонента Camel-Undertow java-фреймворка Apache Camel, позволяющая нарушителю оказать влияние на конфиденциальность и целостность защищаемой информации

EPSS

Процентиль: 30%
0.00112
Низкий

6.5 Medium

CVSS3