CVE Vulnerabilities

CVE-2024-22371

Insecure Storage of Sensitive Information

Published: Feb 26, 2024 | Modified: Oct 31, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
2.9 LOW
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Ubuntu

Exposure of sensitive data by by crafting a malicious EventFactory and providing a custom ExchangeCreatedEvent that exposes sensitive data. Vulnerability in Apache Camel.This issue affects Apache Camel: from 3.21.X through 3.21.3, from 3.22.X through 3.22.0, from 4.0.X through 4.0.3, from 4.X through 4.3.0.

Users are recommended to upgrade to version 3.21.4, 3.22.1, 4.0.4 or 4.4.0, which fixes the issue.

Weakness

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

Affected Software

Name Vendor Start Version End Version
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/logic-data-index-ephemeral-rhel8:1.33.0-5 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/logic-data-index-postgresql-rhel8:1.33.0-5 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/logic-jobs-service-ephemeral-rhel8:1.33.0-5 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/logic-jobs-service-postgresql-rhel8:1.33.0-5 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/logic-kn-workflow-cli-artifacts-rhel8:1.33.0-5 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/logic-operator-bundle:1.33.0-5 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/logic-rhel8-operator:1.33.0-3 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/logic-swf-builder-rhel8:1.33.0-5 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/logic-swf-devmode-rhel8:1.33.0-5 *

References