Bypass/Injection vulnerability in Apache Camel in Camel-Undertow component under particular conditions.
This issue affects Apache Camel: from 4.10.0 before 4.10.3, from 4.8.0 before 4.8.6.
Users are recommended to upgrade to version 4.10.3 for 4.10.x LTS and 4.8.6 for 4.8.x LTS.
Camel undertow component is vulnerable to Camel message header injection, in particular the custom header filter strategy used by the component only filter the "out" direction, while it doesn't filter the "in" direction.
This allows an attacker to include Camel specific headers that for some Camel components can alter the behaviour such as the camel-bean component, or the camel-exec component.
Metrics
Affected Vendors & Products
References
History
Tue, 15 Apr 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache camel |
|
| CPEs | cpe:2.3:a:apache:camel:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Apache
Apache camel |
Wed, 02 Apr 2025 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 01 Apr 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 01 Apr 2025 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Bypass/Injection vulnerability in Apache Camel in Camel-Undertow component under particular conditions. This issue affects Apache Camel: from 4.10.0 before 4.10.3, from 4.8.0 before 4.8.6. Users are recommended to upgrade to version 4.10.3 for 4.10.x LTS and 4.8.6 for 4.8.x LTS. Camel undertow component is vulnerable to Camel message header injection, in particular the custom header filter strategy used by the component only filter the "out" direction, while it doesn't filter the "in" direction. This allows an attacker to include Camel specific headers that for some Camel components can alter the behaviour such as the camel-bean component, or the camel-exec component. | |
| Title | Apache Camel: Camel-Undertow Message Header Injection via Improper Filtering | |
| Weaknesses | CWE-164 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published: 2025-04-01T11:56:30.484Z
Updated: 2025-04-01T18:42:45.532Z
Reserved: 2025-03-17T14:21:01.706Z
Link: CVE-2025-30177
Updated: 2025-04-01T18:42:41.062Z
Status : Analyzed
Published: 2025-04-01T12:15:15.747
Modified: 2025-04-15T13:00:12.587
Link: CVE-2025-30177