← Security advisories
Apache Camel security advisory

CVE-2022-45046

LDAP Injection in camel-ldap

Description

LDAP Injection on camel-ldap component when using the filter option.

Mitigation

Users should upgrade to 3.14.6 or 3.18.4

Credit

This issue was discovered by 4ra1n from Chaitin Tech

Notes

The JIRA ticket: https://issues.apache.org/jira/browse/CAMEL-186906 refers to the various commits that resovoled the issue, and have more details. The camel-spring-ldap component is not affected. Users could use move to the Camel-Spring-Ldap component.

The security vulnerability after further analysis is a false alarm (no security risk) and this CVE is retracted.

References