PT-2026-2851 · Apache+1 · Camel-Neo4J+2
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Apache Camel versions 4.10.0 through 4.10.7
Apache Camel versions 4.14.0 through 4.14.2
Apache Camel versions 4.15.0 through 4.16.9
Description
A Cypher Injection issue exists in the Apache Camel camel-neo4j component. This allows for potential unauthorized access or manipulation of data within a Neo4j database. The issue stems from insufficient input validation when processing Cypher queries. The component is susceptible to malicious Cypher code injection through user-supplied input.
Recommendations
Upgrade to Apache Camel version 4.10.8
Upgrade to Apache Camel version 4.14.3
Upgrade to Apache Camel version 4.17.0
Exploit
Fix
SQL injection
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Camel
Neo4J
Camel-Neo4J