CVE-2025-30177

CWE-1646 documents6 sources
Severity
6.5MEDIUM
EPSS
0.8%
top 25.52%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 1

Description

Bypass/Injection vulnerability in Apache Camel in Camel-Undertow component under particular conditions. This issue affects Apache Camel: from 4.10.0 before 4.10.3, from 4.8.0 before 4.8.6. Users are recommended to upgrade to version 4.10.3 for 4.10.x LTS and 4.8.6 for 4.8.x LTS. Camel undertow component is vulnerable to Camel message header injection, in particular the custom header filter strategy used by the component only filter the "out" direction, while it doesn't filter the "in" directi

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:NExploitability: 3.9 | Impact: 2.5

Affected Packages3 packages

Mavenorg.apache.camel:camel-undertow4.10.04.10.3+1
NVDapache/camel4.8.04.8.6+1
CVEListV5apache_software_foundation/apache_camel4.10.04.10.3+1

🔴Vulnerability Details

3
GHSA
Apache Camel Missing Header Out Filter Leads to Potential Bypass/Injection Vulnerability2025-04-01
OSV
Apache Camel Missing Header Out Filter Leads to Potential Bypass/Injection Vulnerability2025-04-01
CVEList
Apache Camel: Camel-Undertow Message Header Injection via Improper Filtering2025-04-01

📋Vendor Advisories

2
Red Hat
org.apache.camel/camel-undertow: Apache Camel: Camel-Undertow Message Header Injection via Improper Filtering2025-04-01
Apache
Apache camel: CVE-2025-30177