The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerabilities in an interactive lesson.
Start learningUpgrade org.apache.camel:camel-kafka to version 4.14.8, 4.18.3, 4.21.0 or higher.
Affected versions of this package are vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes via the kafka.OVERRIDE_TOPIC and other kafka.* headers that bypass the upstream HTTP header filter. An attacker can redirect messages to arbitrary Kafka topics or inject crafted messages into sensitive topics by supplying specially crafted HTTP headers. This is only exploitable if an HTTP consumer is bridged to a Kafka producer and the HTTP endpoint is unauthenticated.
This vulnerability can be mitigated by stripping kafka.* headers from any untrusted ingress before the Kafka producer, for example by using removeHeaders('kafka.*') at the start of the route, and ensuring the target topic is set from a trusted source.