NA

CVE-2024-22371

Published: 26/02/2024 Updated: 26/02/2024

Vulnerability Summary

Exposure of sensitive data by by crafting a malicious EventFactory and providing a custom ExchangeCreatedEvent that exposes sensitive data. Vulnerability in Apache Camel.This issue affects Apache Camel: from 3.21.X up to and including 3.21.3, from 3.22.X up to and including 3.22.0, from 4.0.X up to and including 4.0.3, from 4.X up to and including 4.3.0. Users are recommended to upgrade to version 3.21.4, 3.22.1, 4.0.4 or 4.4.0, which fixes the issue.

Vulnerability Trend

Mailing Lists

Affected versions: - Apache Camel 1x through 160 unaffected - Apache Camel 321x through 3213 - Apache Camel 322x through 3220 - Apache Camel 40x through 403 - Apache Camel 4x through 430 Description: Exposure of sensitive data by by crafting a malicious EventFactory and providing a custom ExchangeCreatedEvent that exposes sens ...