Improper Handling of Case Sensitivity Affecting org.apache.camel:camel-undertow package, versions [4.8.0,4.8.6)[4.10.0,4.10.3)


Severity

Recommended
0.0
critical
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGAPACHECAMEL-9598038
  • published2 Apr 2025
  • disclosed1 Apr 2025
  • creditMark Thorson

Introduced: 1 Apr 2025

NewCVE-2025-30177  (opens in a new tab)
CWE-178  (opens in a new tab)

How to fix?

Upgrade org.apache.camel:camel-undertow to version 4.8.6, 4.10.3 or higher.

Overview

Affected versions of this package are vulnerable to Improper Handling of Case Sensitivity due to the custom UndertowHeaderFilterStrategy only filtering outgoing and not incoming headers. An attacker can manipulate header entries to invoke arbitrary methods from the Bean registry or use expressions as part of the method parameters, leading to unauthorized actions on components like camel-bean and camel-exec.

This vulnerability is a special case of the vulnerabilities described in CVE-2025-27636 and CVE-2025-29891, applying only to the Undertow component.

CVSS Base Scores

version 4.0
version 3.1