Bug 2429547 (CVE-2025-66169) - CVE-2025-66169 camel-neo4j: Apache Camel camel-neo4j: Unauthorized data modification via Cypher Injection
Summary: CVE-2025-66169 camel-neo4j: Apache Camel camel-neo4j: Unauthorized data modif...
Keywords:
Status: NEW
Alias: CVE-2025-66169
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-01-14 12:01 UTC by OSIDB Bzimport
Modified: 2026-01-21 10:43 UTC (History)
7 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-01-14 12:01:29 UTC
Cypher Injection vulnerability in Apache Camel camel-neo4j component.

This issue affects Apache Camel: from 4.10.0 before 4.10.8, from 4.14.0 before 4.14.3, from 4.15.0 before 4.17.0

Users are recommended to upgrade to version 4.10.8 for 4.10.x LTS and 4.14.3 for 4.14.x LTS and 4.17.0.


Note You need to log in before you can comment on or make changes to this bug.