Improper Input Validation Affecting org.apache.camel:camel-jira package, versions [4.0.0,4.14.8)[4.15.0,4.18.3)[4.19.0,4.21.0)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.35% (27th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGAPACHECAMEL-17875081
  • published7 Jul 2026
  • disclosed6 Jul 2026
  • creditYu Bao

Introduced: 6 Jul 2026

CVE-2026-48206  (opens in a new tab)
CWE-20  (opens in a new tab)

How to fix?

Upgrade org.apache.camel:camel-jira to version 4.14.8, 4.18.3, 4.21.0 or higher.

Overview

Affected versions of this package are vulnerable to Improper Input Validation via the improper handling of Exchange message headers in the JIRA component. An attacker can perform unauthorized JIRA operations by supplying specially crafted HTTP headers, leveraging the endpoint's configured service-account credentials to create, modify, or delete issues, transition issues, or alter project data. This is only exploitable if an HTTP consumer is bridged to a jira: producer and the consumer is unauthenticated.

Workaround

This vulnerability can be mitigated by stripping the relevant control headers (such as IssueKey, ProjectKey, IssueTransitionId, and related headers) from any untrusted ingress before the jira: producer, and setting required JIRA operation parameters from a trusted source.

CVSS Base Scores

version 4.0
version 3.1