CVE-2023-34442: Apache Camel JIRA: Temporary file information disclosure in Camel-Jira
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Camel. This issue affects Apache Camel from 3.X through <=3.14.8, from 3.18.X through <=3.18.7, from 3.20.X through <= 3.20.5, from 4.X through <= 4.0.0-M3.
Users should upgrade to 3.14.9, 3.18.8, 3.20.6 or 3.21.0 and for users on Camel 4.x update to 4.0.0-RC1
Other sources
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Camel.This issue affects Apache Camel: from 3.X through <=3.14.8, from 3.18.X through <=3.18.7, from 3.20.X through <= 3.20.5, from 4.X through <= 4.0.0-M3.
Users should upgrade to 3.14.9, 3.18.8, 3.20.6 or 3.21.0 and for users on Camel 4.x update to 4.0.0-M1
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.apache.camel:camel-jirato a version that resolves this vulnerability.Fixed in 4.0.0-RC1 - Upgrade
Upgrade
maven/org.apache.camel:camel-jirato a version that resolves this vulnerability.Fixed in 3.20.6 - Upgrade
Upgrade
maven/org.apache.camel:camel-jirato a version that resolves this vulnerability.Fixed in 3.18.8 - Upgrade
Upgrade
maven/org.apache.camel:camel-jirato a version that resolves this vulnerability.Fixed in 3.14.9 - Upgrade
Upgrade
Apache Camelto a version that resolves this vulnerability.Fixed in 3.14.9 - Upgrade
Upgrade
Apache Camelto a version that resolves this vulnerability.Fixed in 3.18.8 - Upgrade
Upgrade
Apache Camelto a version that resolves this vulnerability.Fixed in 3.20.6 - Upgrade
Upgrade
Apache Camelto a version that resolves this vulnerability.Fixed in 3.21.0 - Upgrade
Upgrade
Apache Camelto a version that resolves this vulnerability.Fixed in 4.0.0-M1 - Upgrade
Upgrade
Apache Camelto a version that resolves this vulnerability.Fixed in 4.0.0-RC1
Event History
Frequently Asked Questions
What is CVE-2023-34442?
CVE-2023-34442 is a vulnerability that involves exposure of sensitive information to an unauthorized actor in Apache Camel.
Which versions of Apache Camel are affected by CVE-2023-34442?
CVE-2023-34442 affects Apache Camel versions 3.X through <=3.14.8, 3.18.X through <=3.18.7, 3.20.X through <= 3.20.5, and 4.X through <= 4.0.0-M3.
What is the severity of CVE-2023-34442?
The severity of CVE-2023-34442 is low, with a severity value of 3.3.
How do I fix CVE-2023-34442?
To fix CVE-2023-34442, users should upgrade to Apache Camel version 3.14.9 or higher.
Where can I find more information about CVE-2023-34442?
More information about CVE-2023-34442 can be found in the references provided: [link1](https://lists.apache.org/thread/x4vy2hhbltb1xrvy1g6m8hpjgj2k7wgh), [link2](https://nvd.nist.gov/vuln/detail/CVE-2023-34442), [link3](https://github.com/apache/camel/commit/b61d5b6be4f98b673dc977ad1bc6f004642644ab).