Impact
Apache Camel’s CouchDB component contains an input validation flaw that lets non‑Camel‑prefixed Exchange headers bypass the HeaderFilterStrategy. This bypass allows an attacker to overwrite the operation header sent to CouchDB, effectively choosing arbitrary CouchDB operations such as create, delete, or read. The flaw risks data integrity and confidentiality by permitting unauthorized manipulation of the datastore.
Affected Systems
The issue affects the Apache Software Foundation’s Camel product. Versions 4.14.7, 4.15.0 through 4.18.2, and 4.19.0 through 4.20.0 are impacted when the CouchDB component is used. Fixed releases are 4.14.8, 4.18.3, 4.21.0 and later.
Risk and Exploitability
The CVSS score of 7.3 indicates high severity, while the EPSS score of less than 1% signals a low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Because the description does not reveal a specific access path, the likely attack vector is inferred to be remote input to an externally exposed Camel route that forwards CouchDB headers; the attacker would need to supply untrusted header values that override the operation header. This inference is drawn from the nature of the flaw and the component involved.
OpenCVE Enrichment