Apache Camel Under Fire: Multiple RCE Flaws Expose Critical Integration Infrastructure
ID: 4ce8b4b4-db53-5be7-8365-c383feb02755
STIX ID: report--4ce8b4b4-db53-5be7-8365-c383feb02755
Feed Name: securityonline.info
Researchers disclosed multiple critical vulnerabilities in the Apache Camel integration framework that allow unauthenticated or remotely triggered Remote Code Execution through unsafe Java deserialization and header/query-parameter injection across components (Consul, Infinispan, camel-coap, camel-mail, and key lifecycle handling). Several CVEs are noted, including cases where attackers who can write to backing stores or send a single CoAP packet can trigger gadget chains or inject Camel-prefixed headers to execute OS commands; fixes and recommended upgrade versions are provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
