SCA: security update for org.apache.camel:camel-mongodb-gridfs (GHSA-f7g3-2cg6-f5hj)

critical Tenable Self-Hosted Container Security Plugin ID 445370

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Improper Input Validation, Improper Access Control vulnerability in Apache Camel in Camel Mongodb Gridfs
component. The camel-mongodb-gridfs producer selects the GridFS operation to perform from the
gridfs.operation Exchange header when the endpoint's operation parameter is not set - which is the
default. The control-header constants (GridFsConstants.GRIDFS_OPERATION, GRIDFS_OBJECT_ID,
GRIDFS_METADATA, GRIDFS_CHUNKSIZE, GRIDFS_FILE_ID_PRODUCED) were the plain strings gridfs.operation,
gridfs.objectid, gridfs.metadata, gridfs.chunksize and gridfs.fileid. Because these names do not start
with the Camel / camel prefix, HttpHeaderFilterStrategy - which blocks only the Camel header namespace on
the HTTP boundary - let them pass from an inbound HTTP request straight into the Exchange. In a route that
bridges an HTTP consumer (for example platform-http) into a mongodb-gridfs: producer with no explicit
operation, any HTTP client could therefore set the gridfs.operation header to override the route's
intended operation - switching, for example, a file upload to remove (deleting a file identified by the
attacker-supplied gridfs.objectid), listAll (enumerating every file in the bucket) or findOne (reading a
file) - and supply a gridfs.metadata value that is parsed as a MongoDB document, enabling NoSQL operator
injection. No credentials are required when the bridging consumer is unauthenticated. This issue affects
Apache Camel: from 4.0.0 before 4.14.8, from 4.15.0 before 4.18.3, from 4.19.0 before 4.21.0. Users are
recommended to upgrade to version 4.21.0, which fixes the issue. If users are on the 4.14.x LTS releases
stream, then they are suggested to upgrade to 4.14.8. If users are on the 4.18.x releases stream, then
they are suggested to upgrade to 4.18.3. After upgrading, routes that drive GridFS operations or metadata
via the raw header names must use CamelGridFsOperation / CamelGridFsObjectId / CamelGridFsMetadata /
CamelGridFsChunkSize / CamelGridFsFileId instead of the gridfs.* names. For deployments that cannot
upgrade immediately, set an explicit operation on the mongodb-gridfs: endpoint so the operation is not
taken from a header, and strip the gridfs.* headers from any untrusted ingress before the producer.
(CVE-2026-48204)

Solution

Update the org.apache.camel:camel-mongodb-gridfs library and its related packages to version 4.14.8 or later.

See Also

https://github.com/advisories/GHSA-f7g3-2cg6-f5hj

Plugin Details

Severity: Critical

ID: 445370

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 7/25/2026

Updated: 7/25/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.06

Vendor

Vendor Severity: Critical

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-48204

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 7/6/2026

Vulnerability Publication Date: 7/6/2026

Reference Information

CVE: CVE-2026-48204

cwe: CWE-20