Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gv5f-cjw9-5vxg

Опубликовано: 16 окт. 2018
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Camel-xstream component in Apache Camel can allow remote attackers to execute arbitrary commands

The camel-xstream component in Apache Camel before 2.15.5 and 2.16.x before 2.16.1 allow remote attackers to execute arbitrary commands via a crafted serialized Java object in an HTTP request.

Пакеты

Наименование

org.apache.camel:camel-xstream

maven
Затронутые версииВерсия исправления

< 2.15.5

2.15.5

Наименование

org.apache.camel:camel-xstream

maven
Затронутые версииВерсия исправления

= 2.16.0

2.16.1

EPSS

Процентиль: 89%
0.04974
Низкий

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 4.2
redhat
больше 10 лет назад

The camel-xstream component in Apache Camel before 2.15.5 and 2.16.x before 2.16.1 allow remote attackers to execute arbitrary commands via a crafted serialized Java object in an HTTP request.

CVSS3: 9.8
nvd
около 10 лет назад

The camel-xstream component in Apache Camel before 2.15.5 and 2.16.x before 2.16.1 allow remote attackers to execute arbitrary commands via a crafted serialized Java object in an HTTP request.

EPSS

Процентиль: 89%
0.04974
Низкий

9.8 Critical

CVSS3