REDHAT-BUG-2460003: High severity Apache camel-infinispan vulnerability
Unsafe deserialization in camel-infinispan ProtoStream remote aggregation repository. DefaultExchangeHolderUtils.deserialize() uses ClassLoadingAwareObjectInputStream.readObject() without ObjectInputFilter. Same pattern as CVE-2024-22369, CVE-2024-23114, CVE-2026-25747.
Verified on Camel 4.10.0 + Infinispan 15.1.4. Reported to security and MITRE CVE Request #2024308.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2460003?
The severity of REDHAT-BUG-2460003 is considered significant due to the potential for unsafe deserialization vulnerabilities.
How do I fix REDHAT-BUG-2460003?
To fix REDHAT-BUG-2460003, it is recommended to update to the patched versions of Apache camel-infinispan and Infinispan.
What versions are affected by REDHAT-BUG-2460003?
REDHAT-BUG-2460003 affects Apache camel-infinispan version 4.10.0 and Infinispan version 15.1.4.
What methods are associated with the vulnerability REDHAT-BUG-2460003?
The vulnerability REDHAT-BUG-2460003 is associated with the method DefaultExchangeHolderUtils.deserialize() which uses ClassLoadingAwareObjectInputStream.readObject() without an ObjectInputFilter.
Can you provide examples of related vulnerabilities to REDHAT-BUG-2460003?
Related vulnerabilities to REDHAT-BUG-2460003 include CVE-2024-22369, CVE-2024-23114, and CVE-2026-25747.