CVE-2025-30177
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2025-30177 is a bypass/injection vulnerability that affects the Apache Camel's Camel-Undertow component in specific conditions. Affected versions include Apache Camel 4.10.0 to 4.10.2 and 4.8.0 to 4.8.5. This issue can be exploited through Camel message header injection, where the filter strategy used by the component only filters the "out" direction but not the "in" direction. An attacker can include Camel-specific headers that can alter the behavior of certain components, such as camel-bean or camel-exec. Users are advised to upgrade to Apache Camel version 4.10.3 for LTS 4.10.x and 4.8.6 for LTS 4.8.x to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Apache