VDB
Sign up
HIGH7.3

GHSA-5g68-f6xg-vf2r

Apache Camel-CouchDB: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input

Quick fix

GHSA-5g68-f6xg-vf2r — org.apache.camel:camel-couchdb: upgrade to the fixed version with the command below.

# pom.xml: bump <version>4.14.8</version> for org.apache.camel:camel-couchdb

Details

Improper Input Validation vulnerability in Apache Camel.

This issue affects Apache Camel: through 4.14.7, from 4.15.0 through 4.18.2, from 4.19.0 through 4.20.0.

Users are recommended to upgrade to version 4.14.8, 4.18.3, 4.21.0, which fixes the issue.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.apache.camel:camel-couchdb
Introduced in: 4.0.0Fixed in: 4.14.8
Fix# pom.xml: bump <version>4.14.8</version> for org.apache.camel:camel-couchdb
Maven/org.apache.camel:camel-couchdb
Introduced in: 4.15.0Fixed in: 4.18.3
Fix# pom.xml: bump <version>4.18.3</version> for org.apache.camel:camel-couchdb
Maven/org.apache.camel:camel-couchdb
Introduced in: 4.19.0Fixed in: 4.21.0
Fix# pom.xml: bump <version>4.21.0</version> for org.apache.camel:camel-couchdb

References