PT-2026-35386 · Apache · Camel-Infinispan
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Apache Camel versions 4.0.0 through 4.14.6
Apache Camel versions 4.15.0 through 4.18.1
Apache Camel versions 4.19.0 through 4.19.9
Description
A flaw in the
camel-infinispan component allows a remote attacker with write access to the Infinispan cache to execute arbitrary code. The issue occurs when the ProtoStream-based remote aggregation repository deserializes data read from a remote Infinispan cache using the ObjectInputStream function without applying an ObjectInputFilter. By injecting a specially crafted serialized Java object, an attacker can trigger code execution during standard aggregation repository operations, such as get() or recover(), within the application context.Recommendations
Update Apache Camel to version 4.14.7 or later for the 4.0.x branch.
Update Apache Camel to version 4.18.2 or later for the 4.15.x branch.
Update Apache Camel to version 4.20.0 or later for the 4.19.x branch.
Exploit
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Camel-Infinispan