AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2024-22371

LOW · CVSS 2.9 EPSS 0.69%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2024-02-26 · Last synced 2026-08-04

CyberRota Analysis

This is a low severity vulnerability with a CVSS score of 2.9. It affects Exchange, Apache.

CVE
CVE-2024-22371
Severity
LOW
CVSS
2.9
EPSS
0.69%
Exchange Apache

Original NVD Description

Exposure of sensitive data by by crafting a malicious EventFactory and providing a custom ExchangeCreatedEvent that exposes sensitive data. Vulnerability in Apache Camel.This issue affects Apache Camel: from 3.21.X through 3.21.3, from 3.22.X through 3.22.0, from 4.0.X through 4.0.3, from 4.X through 4.3.0. Users are recommended to upgrade to version 3.21.4, 3.22.1, 4.0.4 or 4.4.0, which fixes the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)