The vendor has not yet reached a final affected or unaffected determination for these products.
- camel-salesforce as a component of Red Hat build of Apache Camel 4 for Quarkus 3
- camel-salesforce as a component of Red Hat build of Apache Camel for Spring Boot 4
- camel-salesforce as a component of Red Hat JBoss Enterprise Application Platform Expansion Pack
- Summary
- A flaw was found in Apache Camel Salesforce. Due to improper neutralization of special elements, non-Camel-prefixed HTTP headers are not filtered, allowing them to pass from an inbound HTTP request. A remote, unauthenticated attacker can exploit this by injecting malicious headers to override intended operations. This enables unauthorized access to Salesforce data through custom SOQL/SOSL queries, modification of SObject operations, or redirection of Apex REST calls with the full permissions of the connected Salesforce user.
- Remediation
- No remediation text is recorded.
