Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-22371


Exposure of sensitive data by by crafting a malicious EventFactory and providing a custom ExchangeCreatedEvent that exposes sensitive data. Vulnerability in Apache Camel.This issue affects Apache Camel: from 3.21.X through 3.21.3, from 3.22.X through 3.22.0, from 4.0.X through 4.0.3, from 4.X through 4.3.0. Users are recommended to upgrade to version 3.21.4, 3.22.1, 4.0.4 or 4.4.0, which fixes the issue.


Published

2024-02-26T16:27:56.557

Last Modified

2025-04-25T18:56:25.390

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 2.9 (LOW)

Weaknesses
  • Type: Secondary
    CWE-922

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application apache camel < 3.21.4 Yes
Application apache camel < 4.0.4 Yes
Application apache camel < 4.4.0 Yes
Application apache camel 3.22.0 Yes

References