Impact
Apache Camel is affected by an Improper Input Validation flaw that allows exchange headers lacking a Camel prefix to bypass the HeaderFilterStrategy. This can enable manipulation of operation parameters and potentially override default Camel operations, a weakness classified as CWE-20.
Affected Systems
The vulnerability impacts Apache Camel versions up to and including 4.14.7, as well as 4.15.0 through 4.18.2, and 4.19.0 through 4.20.0. The fix is available in 4.14.8, 4.18.3, and 4.21.0 or later.
Risk and Exploitability
The CVSS score is 7.3, and the vulnerability is not listed in the CISA KEV catalog, indicating no confirmed exploitation yet. The likely attack vector involves an attacker supplying untrusted header values to Camel from an external source. Based on the description, it is inferred that the vulnerability can be leveraged to alter Camel operations, which poses a risk of unauthorized control. The EPSS score of < 1% suggests that exploitation is unlikely without a tailored attack.
OpenCVE Enrichment