Information disclosure in Apache Camel - CVE-2024-22371

 

Information disclosure in Apache Camel - CVE-2024-22371

Published: February 27, 2024


Vulnerability identifier: #VU86861
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-22371
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output by the application when using a malicious EventFactory and providing a custom ExchangeCreatedEven. A remote user can gain unauthorized access to sensitive information on the system.


Affected software

Apache Camel
Jazz for Service Management
IBM Operations Analytics Predictive Insights
IBM Tivoli Netcool Impact
Red Hat Integration Camel Extensions for Quarkus
IBM Cloud Application Performance Management (APM)
Red Hat OpenShift Serverless

How to mitigate CVE-2024-22371

Install updates from vendor's website.

Apache Camel - addressed in versions 3.21.4, 3.22.1, 4.0.4, 4.4.0
Jazz for Service Management - update to 1.1.3.22
IBM Operations Analytics Predictive Insights - update to 1.3.6.8
IBM Tivoli Netcool Impact - update to 7.1.0.34
Red Hat OpenShift Serverless - update to 1.33.0
Red Hat Integration Camel Extensions for Quarkus - update to 3.8.4.SP1
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.17

External References

Related Security Bulletins