Impact
Apache Camel is affected by an Improper Input Validation flaw that allows exchange headers that do not contain the required Camel prefix to bypass the HeaderFilterStrategy. This bypass enables an attacker to manipulate operation parameters and override default Camel operations. The weakness is classified as CWE‑20, and it leads to execution of unauthorized operations through header tampering.
Affected Systems
Apache Camel versions up to 4.14.7, 4.15.0 to 4.18.2, and 4.19.0 to 4.20.0 are affected. The issue is fixed in 4.14.8, 4.18.3, 4.21.0 and later.
Risk and Exploitability
The CVSS score is 7.3 and the EPSS score is under 1 %. The vulnerability is not listed in the CISA KEV catalog. Attackers are likely to supply untrusted header values from an external source; the header bypass would then allow them to alter Camel operation behavior. Although exploitation does not appear to be widespread, the high score indicates that any successful attack could lead to unauthorized operation execution. The low EPSS indicates a low probability of exploitation at present.
OpenCVE Enrichment