PT-2026-2851 · Apache+1 · Apache Camel+2
Ya0H4Cker
·
Published
2026-01-14
·
Updated
2026-01-15
·
CVE-2025-66169
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Apache Camel versions 4.10.0 through 4.10.7
Apache Camel versions 4.14.0 through 4.14.2
Apache Camel versions 4.15.0 through 4.16.9
Description
A Cypher Injection issue exists in the Apache Camel camel-neo4j component. This allows for potential unauthorized access or manipulation of data within a Neo4j database. The issue stems from insufficient input validation when processing Cypher queries. The component is susceptible to malicious Cypher code injection through user-supplied input.
Recommendations
Upgrade to Apache Camel version 4.10.8
Upgrade to Apache Camel version 4.14.3
Upgrade to Apache Camel version 4.17.0
Fix
Special Elements Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Camel
Neo4J
Camel-Neo4J