CVE Vulnerabilities

CVE-2024-22371

Insecure Storage of Sensitive Information

Published: Feb 26, 2024 | Modified: Apr 25, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
2.9 LOW
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Ubuntu

Exposure of sensitive data by by crafting a malicious EventFactory and providing a custom ExchangeCreatedEvent that exposes sensitive data. Vulnerability in Apache Camel.This issue affects Apache Camel: from 3.21.X through 3.21.3, from 3.22.X through 3.22.0, from 4.0.X through 4.0.3, from 4.X through 4.3.0.

Users are recommended to upgrade to version 3.21.4, 3.22.1, 4.0.4 or 4.4.0, which fixes the issue.

Weakness

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

Affected Software

Name Vendor Start Version End Version
Camel Apache 3.0.0 (including) 3.21.4 (excluding)
Camel Apache 4.0.0 (including) 4.0.4 (excluding)
Camel Apache 4.1.0 (including) 4.4.0 (excluding)
Camel Apache 3.22.0 (including) 3.22.0 (including)
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/logic-data-index-ephemeral-rhel8:1.33.0-5 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/logic-data-index-postgresql-rhel8:1.33.0-5 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/logic-jobs-service-ephemeral-rhel8:1.33.0-5 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/logic-jobs-service-postgresql-rhel8:1.33.0-5 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/logic-kn-workflow-cli-artifacts-rhel8:1.33.0-5 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/logic-operator-bundle:1.33.0-5 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/logic-rhel8-operator:1.33.0-3 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/logic-swf-builder-rhel8:1.33.0-5 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/logic-swf-devmode-rhel8:1.33.0-5 *

References