Advisories for Maven/Org.apache.camel/Camel-Salesforce package

2026

Apache Camel-Salesforce: Non-Camel-prefixed Exchange header constants bypass the HTTP header filter

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel Salesforce Component. The camel-salesforce producer resolves its operation parameters - the SOQL query, the SOSL search, the target SObject name and id, the Apex REST URL and method, and the Apex query parameters - from Exchange message headers, reading the header in preference to the value configured on …