Skip to main content

Insecure Storage of Sensitive Information

CVE-2024-22371

Severity High
Score 7.5/10

Summary

Exposure of sensitive data by crafting a malicious "EventFactory" and providing a custom "ExchangeCreatedEvent" that exposes sensitive data. This vulnerability affects org.apache.camel:camel-support package versions 3.0.0-M1 through 3.21.3, 3.22.0, 4.0.0-M1 through 4.0.3, and 4.1.0 through 4.3.0.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • NONE
  • HIGH
  • NONE

CWE-922 - Insecure Storage of Sensitive Information

The software stores sensitive information without properly limiting read or write access by unauthorized actors.

Advisory Timeline

  • Published