CVE-2025-30177

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Apr 1, 2025
Updated: Apr 15, 2025
CWE ID 164

Summary

CVE-2025-30177 is a bypass/injection vulnerability that affects the Apache Camel's Camel-Undertow component in specific conditions. Affected versions include Apache Camel 4.10.0 to 4.10.2 and 4.8.0 to 4.8.5. This issue can be exploited through Camel message header injection, where the filter strategy used by the component only filters the "out" direction but not the "in" direction. An attacker can include Camel-specific headers that can alter the behavior of certain components, such as camel-bean or camel-exec. Users are advised to upgrade to Apache Camel version 4.10.3 for LTS 4.10.x and 4.8.6 for LTS 4.8.x to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share