SB2025032409 - Improper Neutralization of HTTP Headers for Scripting Syntax in Red Hat Camel for Spring Boot 4



SB2025032409 - Improper Neutralization of HTTP Headers for Scripting Syntax in Red Hat Camel for Spring Boot 4

Published: March 24, 2025 Updated: April 11, 2025

Security Bulletin ID SB2025032409
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper Neutralization of HTTP Headers for Scripting Syntax (CVE-ID: CVE-2025-27636)

The vulnerability allows a remote attacker to perform spoofing attack.

The vulnerability exists due to improper input validation when processing HTTP requests, as filters are configured to only block headers starting with "Camel", "camel", or "org.apache.camel". A remote non-authenticated attacker can send a specially crafted HTTP request with altered casing of letters in headers that will be accepted by the application.

Successful exploitation of the vulnerability may allow an attacker to perform cross-site scripting, cache poisoning or session hijacking attacks.


Remediation

Install update from vendor's website.