Apache Camel DNS Vulnerability: SSRF Risk Due to Improper Input Validation
An early warning has been issued regarding a vulnerability in the Apache Camel DNS component that may allow Server-Side Request Forgery (SSRF) due to improper input validation. Users of affected versions are advised to upgrade.
What happened
Reportedly, a critical vulnerability has been identified in the Apache Camel DNS component, tracked under GHSA-HCM8-X79P-WX2W. This vulnerability appears to stem from improper input validation, which could lead to Server-Side Request Forgery (SSRF). An attacker exploiting this flaw may be able to perform internal network reconnaissance by resolving arbitrary internal hostnames. The affected versions include camel-dns (maven) prior to 4.14.8, 4.18.3, or 4.21.0. It is under investigation whether a compromise has occurred. As a recommended action, users are advised to upgrade to Apache Camel version 4.21.0 or, if on the 4.14.x or 4.18.x release streams, upgrade to 4.14.8 or 4.18.3 respectively. Additionally, it is recommended to use CamelDnsServer, CamelDnsName, CamelDnsDomain, CamelDnsType, CamelDnsClass, CamelDnsTerm instead of dns.* / term names in DNS operations. For more detailed information, primary sources should be consulted.
How 0Day mitigates this
camel-dns is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.