CVE-2024-22371
LOWApache Camel <4.4.0 - Info Disclosure
Title source: llmDescription
Exposure of sensitive data by by crafting a malicious EventFactory and providing a custom ExchangeCreatedEvent that exposes sensitive data. Vulnerability in Apache Camel.This issue affects Apache Camel: from 3.21.X through 3.21.3, from 3.22.X through 3.22.0, from 4.0.X through 4.0.3, from 4.X through 4.3.0. Users are recommended to upgrade to version 3.21.4, 3.22.1, 4.0.4 or 4.4.0, which fixes the issue.
Exploits (1)
Scores
CVSS v3
2.9
EPSS
0.0085
EPSS Percentile
75.0%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Details
CWE
CWE-922
Status
published
Products (4)
apache/camel
3.22.0
apache/camel
3.0.0 - 3.21.4
apache/camel
4.0.0 - 4.0.4
org.apache.camel/camel-core
3.0.0 - 3.21.4Maven
Published
Feb 26, 2024
Tracked Since
Feb 18, 2026