Bug 2266024 (CVE-2024-22371) - CVE-2024-22371 camel-core: Exposure of sensitive data by crafting a malicious EventFactory
Summary: CVE-2024-22371 camel-core: Exposure of sensitive data by crafting a malicious...
Keywords:
Status: NEW
Alias: CVE-2024-22371
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 2270598
TreeView+ depends on / blocked
 
Reported: 2024-02-26 11:04 UTC by Rohit Keshri
Modified: 2025-11-11 08:27 UTC (History)
63 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2024:4057 0 None None None 2024-06-24 01:38:46 UTC

Description Rohit Keshri 2024-02-26 11:04:40 UTC
Exposure of sensitive data by by crafting a malicious EventFactory and providing a custom ExchangeCreatedEvent that exposes sensitive data. Vulnerability in Apache Camel.This issue affects Apache Camel: from 3.21.X through 3.21.3, from 3.22.X through 3.22.0, from 4.0.X through 4.0.3, from 4.X through 4.3.0.

Users are recommended to upgrade to version 3.21.4, 3.22.1, 4.0.4 or 4.4.0, which fixes the issue.


References:
https://camel.apache.org/security/CVE-2024-22371.html
https://camel.apache.org/
https://www.cve.org/CVERecord?id=CVE-2024-22371
https://issues.apache.org/jira/browse/CAMEL-20305

Comment 3 errata-xmlrpc 2024-06-24 01:38:41 UTC
This issue has been addressed in the following products:

  RHOSS-1.33-RHEL-8

Via RHSA-2024:4057 https://access.redhat.com/errata/RHSA-2024:4057


Note You need to log in before you can comment on or make changes to this bug.