Bypass/Injection vulnerability in Apache Camel in Camel-Undertow component under particular conditions.
This issue affects Apache Camel: from 4.10.0 before 4.10.3, from 4.8.0 before 4.8.6.
Users are recommended to upgrade to version 4.10.3 for 4.10.x LTS and 4.8.6 for 4.8.x LTS.
Camel undertow component is vulnerable to Camel message header injection, in particular the custom header filter strategy used by the component only filter the "out" direction, while it doesn't filter the "in" direction.
This allows an attacker to include Camel specific headers that for some Camel components can alter the behaviour such as the camel-bean component, or the camel-exec component.
                
            Metrics
Affected Vendors & Products
References
        History
                    Tue, 15 Apr 2025 13:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Apache Apache camel | |
| CPEs | cpe:2.3:a:apache:camel:*:*:*:*:*:*:*:* | |
| Vendors & Products | Apache Apache camel | 
Wed, 02 Apr 2025 02:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References |  | |
| Metrics | threat_severity 
 | threat_severity 
 | 
Tue, 01 Apr 2025 19:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | cvssV3_1 
 
 | 
Tue, 01 Apr 2025 12:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | Bypass/Injection vulnerability in Apache Camel in Camel-Undertow component under particular conditions. This issue affects Apache Camel: from 4.10.0 before 4.10.3, from 4.8.0 before 4.8.6. Users are recommended to upgrade to version 4.10.3 for 4.10.x LTS and 4.8.6 for 4.8.x LTS. Camel undertow component is vulnerable to Camel message header injection, in particular the custom header filter strategy used by the component only filter the "out" direction, while it doesn't filter the "in" direction. This allows an attacker to include Camel specific headers that for some Camel components can alter the behaviour such as the camel-bean component, or the camel-exec component. | |
| Title | Apache Camel: Camel-Undertow Message Header Injection via Improper Filtering | |
| Weaknesses | CWE-164 | |
| References |  | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: apache
Published: 2025-04-01T11:56:30.484Z
Updated: 2025-04-01T18:42:45.532Z
Reserved: 2025-03-17T14:21:01.706Z
Link: CVE-2025-30177
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-04-01T18:42:41.062Z
 NVD
                        NVD
                    Status : Analyzed
Published: 2025-04-01T12:15:15.747
Modified: 2025-04-15T13:00:12.587
Link: CVE-2025-30177
 Redhat
                        Redhat