GHSA-qpxm-689r-3849 · Severity: low · Ecosystem: maven — Apache Camel data exposure vulnerability
Exposure of sensitive data by by crafting a malicious EventFactory and providing a custom ExchangeCreatedEvent that exposes sensitive data. Vulnerability in Apache Camel.This issue affects Apache Camel: from 3.21.X through 3.21.3, from 3.22.X through 3.22.0, from 4.0.X through 4.0.3, from 4.X through 4.3.0. Users are recommended to upgrade to version 3.21.4, 3.22.1, 4.0.4 or 4.4.0, which fixes the issue.
Conclusion & alert: CVE-2024-22371 is rated Low Risk (38/100): CVSS Low severity, with medium exploitation likelihood (EPSS 0.85%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-04-05 | 0.68% | 0.85% | +0.17% |
| 2 | 2026-03-16 | 0.58% | 0.68% | +0.10% |
| 3 | 2025-12-09 | — | 0.58% | — |
Full EPSS history (10 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 2.9 | 3.1 | LOW |
|
1.4 | 1.4 | [email protected] |
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
GHSA-qpxm-689r-3849 · Severity: low · Ecosystem: maven — Apache Camel data exposure vulnerability
| vendor | priority | summary | link |
|---|---|---|---|
redhat
|
low | — | https://access.redhat.com/security/cve/CVE-2024-22371 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| apache | camel | >= 3.0.0, < 3.21.4 | cpe:2.3:a:apache:camel:*:*:*:*:*:*:*:* |
| apache | camel | >= 4.0.0, < 4.0.4 | cpe:2.3:a:apache:camel:*:-:*:*:*:*:*:* |
| apache | camel | >= 4.1.0, < 4.4.0 | cpe:2.3:a:apache:camel:*:*:*:*:*:*:*:* |
| apache | camel | 3.22.0 | cpe:2.3:a:apache:camel:3.22.0:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://camel.apache.org/security/CVE-2024-22371.html | Vendor Advisory |