Skip to content

[FP]: The scanner flags older CVEs in fixed camel version 3.22.4 #8589

@er-balaji

Description

@er-balaji

Package URl

pkg:maven/org.apache.camel/camel-core@3.22.4

CPE

cpe:2.3:a:apache:camel:3.22.4:::::::*

CVE

CVE-2024-22369, CVE-2024-23114, CVE-2025-27636

ODC Integration

None

ODC Version

12.2.1

Description

The scanner flags Apache Camel 3.22.4 for these CVEs, but all three were fixed in versions ≤3.22.4:

Scanner does not correctly evaluate fix version boundaries.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions