Description
Exposure of sensitive data by by crafting a malicious EventFactory and providing a custom ExchangeCreatedEvent that exposes sensitive data. Vulnerability in Apache Camel.This issue affects Apache Camel: from 3.21.X through 3.21.3, from 3.22.X through 3.22.0, from 4.0.X through 4.0.3, from 4.X through 4.3.0. Users are recommended to upgrade to version 3.21.4, 3.22.1, 4.0.4 or 4.4.0, which fixes the issue.
CVSS breakdown
CVSS 3.1
Attack Vector
Local
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Affected products
- Apache Software Foundation / Apache Camel1.x – 1.6.0
- Apache Software Foundation / Apache Camel3.21.x – 3.21.3
- Apache Software Foundation / Apache Camel3.22.x – 3.22.0
- Apache Software Foundation / Apache Camel4.0.x – 4.0.3
- Apache Software Foundation / Apache Camel4.x – 4.3.0