CVE-2023-34442

Source
https://cve.org/CVERecord?id=CVE-2023-34442
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-34442.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-34442
Aliases
Published
2023-07-10T09:31:05.286Z
Modified
2026-07-15T02:09:49.988214194Z
Summary
Apache Camel JIRA: Temporary file information disclosure in Camel-Jira
Details

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Camel.This issue affects Apache Camel: from 3.X through <=3.14.8, from 3.18.X through <=3.18.7, from 3.20.X through <= 3.20.5, from 4.X through <= 4.0.0-M3.

Users should upgrade to 3.14.9, 3.18.8, 3.20.6 or 3.21.0 and for users on Camel 4.x update to 4.0.0-M1

Database specific
{
    "cwe_ids": [
        "CWE-200"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/34xxx/CVE-2023-34442.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "3.x"
                },
                {
                    "last_affected": "<=3.14.8"
                },
                {
                    "introduced": "3.18.x"
                },
                {
                    "last_affected": "<=3.18.7"
                },
                {
                    "introduced": "3.20.x"
                },
                {
                    "last_affected": "<= 3.20.5"
                },
                {
                    "introduced": "4.x"
                },
                {
                    "last_affected": "<= 4.0.0-M3"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ],
    "cna_assigner": "apache"
}
References

Affected packages

Git / github.com/apache/camel

Affected ranges

Type
GIT
Repo
https://github.com/apache/camel
Events
Database specific
{
    "cpe": [
        "cpe:2.3:a:apache:camel:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:camel:4.0.0:milestone1:*:*:*:*:*:*",
        "cpe:2.3:a:apache:camel:4.0.0:milestone2:*:*:*:*:*:*",
        "cpe:2.3:a:apache:camel:4.0.0:milestone3:*:*:*:*:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "3.0.0"
        },
        {
            "fixed": "3.14.9"
        },
        {
            "introduced": "3.18.0"
        },
        {
            "fixed": "3.18.8"
        },
        {
            "introduced": "3.20.0"
        },
        {
            "fixed": "3.20.6"
        },
        {
            "introduced": "4.0.0-milestone1"
        },
        {
            "last_affected": "4.0.0-milestone1"
        },
        {
            "introduced": "4.0.0-milestone2"
        },
        {
            "last_affected": "4.0.0-milestone2"
        },
        {
            "introduced": "4.0.0-milestone3"
        },
        {
            "last_affected": "4.0.0-milestone3"
        }
    ],
    "source": [
        "CPE_RANGE",
        "CPE_STRING"
    ]
}

Affected versions

4.*
4.0.0-milestone1
4.0.0-milestone2
4.0.0-milestone3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-34442.json"