Apache Camel JIRA: Temporary file information disclosure in Camel-Jira
CVE-2023-34442

3.3LOW

Key Information:

Vendor
Apache
Vendor
CVE Published:
10 July 2023

Summary

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Camel.This issue affects Apache Camel: from 3.X through <=3.14.8, from 3.18.X through <=3.18.7, from 3.20.X through <= 3.20.5, from 4.X through <= 4.0.0-M3.

Users should upgrade to 3.14.9, 3.18.8, 3.20.6 or 3.21.0 and for users on Camel 4.x update to 4.0.0-M1

Affected Version(s)

Apache Camel JIRA 3.x

Apache Camel JIRA 3.18.x

Apache Camel JIRA 3.20.x

References

CVSS V3.1

Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jonathan Leitschuh of the Open Source Security Foundation: Project Alpha-Omega
.