GHSA-m43p-55rf-8c2j · Severity: high · Ecosystem: maven — Deserialization of Untrusted Data in Apache Camel CassandraQL
Deserialization of Untrusted Data vulnerability in Apache Camel CassandraQL Component AggregationRepository which is vulnerable to unsafe deserialization. Under specific conditions it is possible to deserialize malicious payload.This issue affects Apache Camel: from 3.0.0 before 3.21.4, from 3.22.0 before 3.22.1, from 4.0.0 before 4.0.4, from 4.1.0 before 4.4.0. Users are recommended to upgrade to version 4.4.0, which fixes the issue. If users are on the 4.0.x LTS releases stream, then they are suggested to upgrade to 4.0.4. If users are on 3.x, they are suggested to move to 3.21.4 or 3.22.1
Conclusion & alert: CVE-2024-23114 is rated Moderate Risk (60.8/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 1.14%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 1.35% | 1.14% | -0.21% |
| 2 | 2026-05-26 | 1.39% | 1.35% | -0.04% |
| 3 | 2026-05-22 | — | 1.39% | — |
Full EPSS history (20 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
GHSA-m43p-55rf-8c2j · Severity: high · Ecosystem: maven — Deserialization of Untrusted Data in Apache Camel CassandraQL
| vendor | priority | summary | link |
|---|---|---|---|
redhat
|
high | — | https://access.redhat.com/security/cve/CVE-2024-23114 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| apache | camel | >= 3.0.0, < 3.21.4 | cpe:2.3:a:apache:camel:*:*:*:*:*:*:*:* |
| apache | camel | >= 4.0.0, < 4.0.4 | cpe:2.3:a:apache:camel:*:*:*:*:*:*:*:* |
| apache | camel | >= 4.1.0, < 4.4.0 | cpe:2.3:a:apache:camel:*:*:*:*:*:*:*:* |
| apache | camel | 3.22.0 | cpe:2.3:a:apache:camel:3.22.0:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://camel.apache.org/security/CVE-2024-23114.html | Vendor Advisory |