Insecure Storage of Sensitive Information
CVE-2024-22371
Summary
Exposure of sensitive data by crafting a malicious "EventFactory" and providing a custom "ExchangeCreatedEvent" that exposes sensitive data. This vulnerability affects org.apache.camel:camel-support package versions 3.0.0-M1 through 3.21.3, 3.22.0, 4.0.0-M1 through 4.0.3, and 4.1.0 through 4.3.0.
- LOW
- NETWORK
- NONE
- UNCHANGED
- NONE
- NONE
- HIGH
- NONE
CWE-922 - Insecure Storage of Sensitive Information
The software stores sensitive information without properly limiting read or write access by unauthorized actors.
Advisory Timeline
- Published