Skip to content

Commit 562bb4c

Browse files
Sync Collecting Fix Commits: Thu May 21 12:49:24 UTC 2026
Signed-off-by: AboutCode Automation <automation@aboutcode.org>
1 parent d858113 commit 562bb4c

4 files changed

Lines changed: 26 additions & 21 deletions

File tree

data/fix-commits/advisory-database-b78f1d41.json

Lines changed: 14 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,16 @@
11
{
22
"vcs_url": "https://github.com/github/advisory-database",
33
"vulnerabilities": {
4+
"GHSA-VJR5-C9QV-HGM3": {
5+
"fb6ff6e08b1728bdb5447bfe357abaadd8343ace": "Improve GHSA-vjr5-c9qv-hgm3",
6+
"2c2c5f534f13750d0cc92a57eaf31a4f7dc6bc7c": "Publish GHSA-vjr5-c9qv-hgm3",
7+
"a00247405b093a98b9a5a1b3068d73e4e6ef69dd": "Publish Advisories\n\nGHSA-6j7p-qjhg-9947\nGHSA-vjr5-c9qv-hgm3"
8+
},
9+
"GHSA-6J7P-QJHG-9947": {
10+
"10f589ee0ed9ced41fc71d82bd01798ed4c0eb0f": "Improve GHSA-6j7p-qjhg-9947",
11+
"faf6b48ee71b29e8b3096349acf7c030782fd121": "Publish Advisories\n\nGHSA-jr22-8qgm-4q87\nGHSA-6j7p-qjhg-9947\nGHSA-f2qx-66wf-wvvx",
12+
"a00247405b093a98b9a5a1b3068d73e4e6ef69dd": "Publish Advisories\n\nGHSA-6j7p-qjhg-9947\nGHSA-vjr5-c9qv-hgm3"
13+
},
414
"GHSA-2VWV-VQPV-V8VC": {
515
"f74ba8ef1bbe16b7b41a9579615184484c80e7ce": "Publish Advisories\n\nGHSA-2vwv-vqpv-v8vc\nGHSA-9pr2-m366-8728\nGHSA-c75f-55f6-f63q\nGHSA-3q6m-7jw2-r5m4\nGHSA-c7gm-xj5j-p869\nGHSA-f53p-382v-8pj7\nGHSA-w5xq-c4pf-ghq7",
616
"59d85796504a643f73c24a34ebfde1b7905b14fa": "Publish Advisories\n\nGHSA-2vwv-vqpv-v8vc\nGHSA-c75f-55f6-f63q\nGHSA-3xrw-97cx-wwgf\nGHSA-8p2w-g92w-f4x3\nGHSA-fwp8-962p-2xcc\nGHSA-g3jr-4jrm-jvqv\nGHSA-g6xr-2p64-fh4g\nGHSA-gm85-wrgm-h2qc\nGHSA-j72f-vgmh-c8hr\nGHSA-mv66-6hmr-f6wq\nGHSA-mw27-v6r3-mmpp\nGHSA-pprv-j56w-x96f\nGHSA-r9x2-mg2v-mq96\nGHSA-rv9h-9wv4-5fxx\nGHSA-vm5f-653c-mwv3\nGHSA-wcg3-35qx-r9pp\nGHSA-x9j3-g3hc-fc94\nGHSA-xccp-97wp-3gjg\nGHSA-xh36-jjpq-3cmr\nGHSA-xm8v-8xxf-7x94",
@@ -255,16 +265,15 @@
255265
"GHSA-HMGX-5P26-CCF2": {
256266
"200221f7bd23f3d4e11cf95a3d55c0adeeba309d": "Improve GHSA-hmgx-5p26-ccf2"
257267
},
268+
"GHSA-QM24-4869-99PJ": {
269+
"e96741a0a5efff8cbc07da99a6c2f9fc7c6f6cd3": "Improve GHSA-qm24-4869-99pj",
270+
"2baa893b341ec1e5ba36025be30b5bbe398ace6d": "Publish Advisories\n\nGHSA-qm24-4869-99pj\nGHSA-qm24-4869-99pj"
271+
},
258272
"GHSA-HCF7-66RW-9F5R": {
259-
"b9a620ab3e621527ac72cfef5c7353d9581d1b0b": "Improve GHSA-hcf7-66rw-9f5r",
260273
"506c43475711209fd5d3b800dd122ab9c3054304": "Improve GHSA-hcf7-66rw-9f5r",
261274
"7f41e3d5486a21d81e8ef082bf59cfd9f8762cd2": "Improve GHSA-hcf7-66rw-9f5r",
262275
"94db7bb23e4c927cdb29b6e3f66c2d88e6abe52b": "Publish Advisories\n\nGHSA-3qcw-2rhx-2726\nGHSA-hcf7-66rw-9f5r"
263276
},
264-
"GHSA-QM24-4869-99PJ": {
265-
"e96741a0a5efff8cbc07da99a6c2f9fc7c6f6cd3": "Improve GHSA-qm24-4869-99pj",
266-
"2baa893b341ec1e5ba36025be30b5bbe398ace6d": "Publish Advisories\n\nGHSA-qm24-4869-99pj\nGHSA-qm24-4869-99pj"
267-
},
268277
"GHSA-V348-VR4Q-FV9P": {
269278
"8cd26ca3257bd3badb038748a94c8be5e11b15bb": "Improve GHSA-v348-vr4q-fv9p"
270279
},
@@ -5668,10 +5677,6 @@
56685677
"d9ceca09834d547ad8655faf5edbb6f9fba4d163": "Publish Advisories\n\nGHSA-hg35-mp25-qf6h\nGHSA-jr22-8qgm-4q87",
56695678
"2cd2ecc4e9ed37c3bbcef7d3eb404c760346fbd9": "Publish Advisories\n\nGHSA-fgxv-gw55-r5fq\nGHSA-hg35-mp25-qf6h\nGHSA-jr22-8qgm-4q87\nGHSA-r4pf-3v7r-hh55\nGHSA-hg35-mp25-qf6h\nGHSA-jr22-8qgm-4q87"
56705679
},
5671-
"GHSA-6J7P-QJHG-9947": {
5672-
"faf6b48ee71b29e8b3096349acf7c030782fd121": "Publish Advisories\n\nGHSA-jr22-8qgm-4q87\nGHSA-6j7p-qjhg-9947\nGHSA-f2qx-66wf-wvvx",
5673-
"a00247405b093a98b9a5a1b3068d73e4e6ef69dd": "Publish Advisories\n\nGHSA-6j7p-qjhg-9947\nGHSA-vjr5-c9qv-hgm3"
5674-
},
56755680
"GHSA-F2QX-66WF-WVVX": {
56765681
"faf6b48ee71b29e8b3096349acf7c030782fd121": "Publish Advisories\n\nGHSA-jr22-8qgm-4q87\nGHSA-6j7p-qjhg-9947\nGHSA-f2qx-66wf-wvvx"
56775682
},
@@ -7044,10 +7049,6 @@
70447049
"cd0cc44790b6c94a79e5976ec847638594824bf0": "Publish GHSA-8mp2-v27r-99xp",
70457050
"245b936b8f0fa2c32764ebe48a315852a8ad5a0b": "Publish GHSA-8mp2-v27r-99xp"
70467051
},
7047-
"GHSA-VJR5-C9QV-HGM3": {
7048-
"2c2c5f534f13750d0cc92a57eaf31a4f7dc6bc7c": "Publish GHSA-vjr5-c9qv-hgm3",
7049-
"a00247405b093a98b9a5a1b3068d73e4e6ef69dd": "Publish Advisories\n\nGHSA-6j7p-qjhg-9947\nGHSA-vjr5-c9qv-hgm3"
7050-
},
70517052
"GHSA-68J8-PQ59-FQGM": {
70527053
"439b64354fe2e4289e1e7aaeb7a93e69f8629a24": "Publish Advisories\n\nGHSA-68j8-pq59-fqgm\nGHSA-4j28-22qp-rjcf\nGHSA-vc5j-42hh-j3mr\nGHSA-3r34-vq8m-39gh"
70537054
},

data/fix-commits/camel-36fc325a.json

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2,6 +2,7 @@
22
"vcs_url": "https://github.com/apache/camel",
33
"vulnerabilities": {
44
"CVE-2025-27636": {
5+
"725175e3aa16216361acc8497345f8e00536d2e0": "CAMEL-23522: camel-mail - gate JavaMail session properties from headers behind opt-in (#23362) (#23381)\n\nMailProducer.getSender extracted mail.smtp.* / mail.smtps. exchange headers and applied them as\nJavaMail session properties on a per-message custom sender. The namespace is Camel-internal\n(only MailProducer interprets it) and is not filtered by any HeaderFilterStrategy, so a route\nchaining an untrusted producer (platform-http, JMS, Kafka, ...) into smtp/smtps without an\nexplicit removeHeaders between them let an attacker drive transport-security settings\n(mail.smtp.ssl.trust, mail.smtp.starttls.enable, mail.smtp.socks.host, ...).\n\nThis is the same conceptual pattern as the Camel* header injection family (CAMEL-23222 /\nCVE-2025-27636), with a namespace that was missed in that sweep.\n\nChanges:\n\n* New @UriParam useJavaMailSessionPropertiesFromHeaders (default false, label\n producer,advanced,security, security=insecure:ssl) on MailConfiguration. When false,\n MailProducer.getSender always returns the default sender.\n* MailHeaderFilterStrategy now also filters mail.smtp. / mail.smtps. on the inbound path\n (defense in depth, mirroring CAMEL-23222).\n* Doc note in mail-component.adoc with the security warning and the opt-in URI.\n* Upgrade-guide entry in camel-4x-upgrade-guide-4_21.adoc.\n* Tests for both flag values and for the header-filter strategy behaviour.\n\nThe build's SECURITY-OPTIONS generator picked up the new annotation and added the property to\nthe policy-enforceable map in core/camel-util SecurityUtils.\n\nSigned-off-by: Andrea Cosentino <ancosen@gmail.com>",
56
"1e31abca3213cde447a2ded1adc070ffec6836f1": "CAMEL-23522: camel-mail - gate JavaMail session properties from headers behind opt-in (#23362)\n\nMailProducer.getSender extracted mail.smtp.* / mail.smtps. exchange headers and applied them as\nJavaMail session properties on a per-message custom sender. The namespace is Camel-internal\n(only MailProducer interprets it) and is not filtered by any HeaderFilterStrategy, so a route\nchaining an untrusted producer (platform-http, JMS, Kafka, ...) into smtp/smtps without an\nexplicit removeHeaders between them let an attacker drive transport-security settings\n(mail.smtp.ssl.trust, mail.smtp.starttls.enable, mail.smtp.socks.host, ...).\n\nThis is the same conceptual pattern as the Camel* header injection family (CAMEL-23222 /\nCVE-2025-27636), with a namespace that was missed in that sweep.\n\nChanges:\n\n* New @UriParam useJavaMailSessionPropertiesFromHeaders (default false, label\n producer,advanced,security, security=insecure:ssl) on MailConfiguration. When false,\n MailProducer.getSender always returns the default sender.\n* MailHeaderFilterStrategy now also filters mail.smtp. / mail.smtps. on the inbound path\n (defense in depth, mirroring CAMEL-23222).\n* Doc note in mail-component.adoc with the security warning and the opt-in URI.\n* Upgrade-guide entry in camel-4x-upgrade-guide-4_21.adoc.\n* Tests for both flag values and for the header-filter strategy behaviour.\n\nThe build's SECURITY-OPTIONS generator picked up the new annotation and added the property to\nthe policy-enforceable map in core/camel-util SecurityUtils.\n\nSigned-off-by: Andrea Cosentino <ancosen@gmail.com>",
67
"7005e4f55b11ed40a4ef73295b2fbe0082e7cfeb": "docs: add core router-engine invariants to the security model (#23282)\n\n* docs: add core router-engine invariants to the security model\n\nAdds a \"Core router-engine invariants\" subsection to the project\nsecurity model. The existing \"Security properties and violation\nseverity\" table is the cross-component impact view; this companion\nsubsection states what camel-core itself - the routing engine, the\nExchange/Message model, the EIP processors, expression / language /\nproperty-placeholder resolution, and the type-converter and\ndata-format registries - upholds independently of any one component,\nso a candidate located in a core/camel-* module can be routed to a\nproperty and a triage disposition without re-deriving the trust model.\n\nStrict superset, no behavioural or scope change: each invariant is the\nengine-layer projection of an in-scope vulnerability class or of the\ndocumented trust boundary already in the model (expression/template\ninjection; Camel-header / bean-dispatch abuse; unsafe deserialisation,\nincl. CVE-2015-0263; the CVE-2025-27636 header-promotion family; and\nthe management-surface and DoS out-of-scope items). Documentation\nonly; it closes the shallowness in the properties section for\ncore-engine findings raised by automated security triage.\n\n_Claude Code (Opus 4.7) on behalf of Andrea Cosentino_\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>\n\n* docs: scope the dev/test profile out of the security model\n\nAddresses review feedback from @davsclaus on PR #23282: make explicit,\nas a triage rule, what was previously only stated as a hardening\nresponsibility - that the non-default `dev` / `test` profile (set via\ncamel.main.profile, or selected by tooling such as Camel JBang) is\ndevelopment-only and deliberately less guarded, and that Camel may by\ndesign reveal configuration, route and Exchange detail in those modes\nthat it would not reveal under the default `prod` profile.\n\nAdds one bullet to \"Out of scope\": a report whose impact only manifests\nunder camel.main.profile=dev/test is out of scope as a non-default,\ndevelopment-only configuration; the production posture against which\nfindings are judged is the default `prod` profile. Cross-references the\nexisting Deployment hardening bullet and proposals/security.adoc. No\nbehavioural change; documentation only.\n\n_Claude Code (Opus 4.7) on behalf of Andrea Cosentino_\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>"
78
},

0 commit comments

Comments
 (0)