Bypass/Injection vulnerability in Apache Camel in Camel-Undertow component under particular conditions.
This issue affects Apache Camel: from 4.10.0 before 4.10.3, from 4.8.0 before 4.8.6.
Users are recommended to upgrade to version 4.10.3 for 4.10.x LTS and 4.8.6 for 4.8.x LTS.
Camel undertow component is vulnerable to Camel message header injection, in particular the custom header filter strategy used by the component only filter the "out" direction, while it doesn't filter the "in" direction.
This allows an attacker to include Camel specific headers that for some Camel components can alter the behaviour such as the camel-bean component, or the camel-exec component.
Metrics
Affected Vendors & Products
References
History
Tue, 15 Apr 2025 13:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Apache
Apache camel |
|
CPEs | cpe:2.3:a:apache:camel:*:*:*:*:*:*:*:* | |
Vendors & Products |
Apache
Apache camel |
Wed, 02 Apr 2025 02:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
threat_severity
|
Tue, 01 Apr 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Tue, 01 Apr 2025 12:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Bypass/Injection vulnerability in Apache Camel in Camel-Undertow component under particular conditions. This issue affects Apache Camel: from 4.10.0 before 4.10.3, from 4.8.0 before 4.8.6. Users are recommended to upgrade to version 4.10.3 for 4.10.x LTS and 4.8.6 for 4.8.x LTS. Camel undertow component is vulnerable to Camel message header injection, in particular the custom header filter strategy used by the component only filter the "out" direction, while it doesn't filter the "in" direction. This allows an attacker to include Camel specific headers that for some Camel components can alter the behaviour such as the camel-bean component, or the camel-exec component. | |
Title | Apache Camel: Camel-Undertow Message Header Injection via Improper Filtering | |
Weaknesses | CWE-164 | |
References |
|

Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-04-01T18:42:45.532Z
Reserved: 2025-03-17T14:21:01.706Z
Link: CVE-2025-30177

Updated: 2025-04-01T18:42:41.062Z

Status : Analyzed
Published: 2025-04-01T12:15:15.747
Modified: 2025-04-15T13:00:12.587
Link: CVE-2025-30177
