Users are recommended to upgrade to version 4.4.0, which fixes the issue. If users are on the 4.0.x LTS releases stream, then they are suggested to upgrade to 4.0.4. If users are on 3.x, they are suggested to move to 3.21.4 or 3.22.1
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-36xr-4x2f-cfj9 | Deserialization of Untrusted Data in Apache Camel SQL |
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 02 Apr 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:apache:camel:*:*:*:*:*:*:*:* |
Tue, 05 Nov 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache camel |
|
| CPEs | cpe:2.3:a:apache:camel:3.0.0:-:*:*:*:*:*:* cpe:2.3:a:apache:camel:3.22.0:*:*:*:*:*:*:* cpe:2.3:a:apache:camel:4.0.0:*:*:*:*:*:*:* cpe:2.3:a:apache:camel:4.1.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Apache
Apache camel |
|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-11-05T19:47:09.797Z
Reserved: 2024-01-09T09:46:19.456Z
Link: CVE-2024-22369
Updated: 2024-08-01T22:43:34.477Z
Status : Analyzed
Published: 2024-02-20T15:15:10.113
Modified: 2025-04-02T20:17:04.160
Link: CVE-2024-22369
OpenCVE Enrichment
No data.
Github GHSA