CVE-2024-22369 is a deserialization of untrusted data vulnerability in the Apache Camel SQL component, specifically in JDBCAggregationRepository. Affected Apache Camel versions can deserialize attacker-controlled serialized data under specific conditions, exposing the application to unsafe Java deserialization behavior. The flaw is part of a broader class of Camel aggregation repository deserialization issues in which serialized objects are read without sufficient validation or filtering, enabling malicious payloads to be processed by the application.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small Spring Boot/Java proof-of-concept reproducer for CVE-2026-27172, a Java deserialization vulnerability in Apache Camel's camel-consul ConsulRegistry. The project is not a scanner or detection script; it actively demonstrates exploitation by exposing REST endpoints that initialize a Consul-backed registry entry, overwrite that entry with attacker-supplied Base64 serialized data, and then trigger Camel's vulnerable lookup path. Repository structure: pom.xml defines a Maven Spring Boot application using Java 17, camel-consul-starter and camel-spring-boot-starter at Camel 4.18.0 (explicitly vulnerable per the README), plus commons-collections 3.2.1 to ensure a gadget chain is present. Application.java is the Spring Boot entry point. ExploitController.java is the main exploit logic and the effective entry point for the PoC. ConsulRegistryRoute.java is intentionally disabled and only documents how a real Camel route would invoke lookupByName() during bean resolution. application.properties sets the web server to port 8080. Main exploit capabilities: ExploitController exposes GET /exploit/init to create a legitimate serialized value in Consul under key myProcessor using ConsulRegistry.put(); POST /exploit/inject to overwrite that same Consul KV key with an attacker-provided Base64 payload; GET /exploit/trigger to call ConsulRegistry.lookupByName("myProcessor"), which causes Base64 decoding and unsafe ObjectInputStream.readObject() deserialization in affected Camel versions; and GET /exploit/cleanup to remove the key. The exploit therefore demonstrates arbitrary code execution through attacker-controlled data in the Consul KV store when the application performs a registry lookup. Attack path: the attacker needs the ability to write to the Consul KV store used by the Camel application. Once a malicious serialized object is stored under a key that Camel resolves, any subsequent lookupByName()/lookupByNameAndType()/findByType* path can deserialize the payload. The README shows a ysoserial-generated CommonsCollections7 payload executing a benign command (touch /tmp/pwned), but the mechanism is generic arbitrary command execution via Java gadget chains. Notable endpoints and targets: the PoC app listens on localhost:8080 and uses a local Consul agent at http://localhost:8500. The specific Consul KV key targeted is myProcessor. The exploit is both web-exposed (through the PoC controller) and network-oriented (through interaction with the Consul service).
This repository is a Proof-of-Concept (PoC) exploit for CVE-2024-22369, a Java deserialization vulnerability in Apache Camel's JdbcAggregationRepository. The exploit demonstrates how an attacker can inject a malicious serialized Java object (generated with ysoserial and CommonsCollections7) into a MySQL database table used by Camel for aggregation. When the vulnerable Camel application reads and deserializes this object, it can trigger arbitrary code execution (e.g., launching 'gedit'). The repository includes: - SQL scripts (employee.sql, employee_completed.sql) to set up the required database tables and insert the malicious payload. - A Spring Boot/Apache Camel Java application that connects to the MySQL database and uses JdbcAggregationRepository for message aggregation. - Instructions in the README.md for setting up the environment, generating the payload, and running the exploit. Key endpoints include the MySQL database (default IP: 172.17.0.2), the JDBC connection string, and the application properties file. The exploit requires the attacker to have the ability to insert crafted payloads into the database, making the primary attack vector local or network-based depending on database exposure. The PoC does not provide a remote exploit chain but demonstrates the vulnerability's impact in a controlled environment.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A previously addressed vulnerability of the same class referenced for comparison/background.
A previously identified vulnerability mentioned for comparison as having the same unsafe deserialization pattern.
A previously addressed Apache Camel vulnerability of the same class as the issue discussed, referenced for similarity only.
A previously addressed vulnerability of the same class referenced for comparison only; no further details are provided in the content.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.