Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x9fv-c87w-55wc

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью

Описание

Improper Control of Generation of Code in Apache Camel

Apache Camel before 2.9.7, 2.10.0 before 2.10.7, 2.11.0 before 2.11.2, and 2.12.0 allows remote attackers to execute arbitrary simple language expressions by including "$simple{}" in a CamelFileName message header to a (1) FILE or (2) FTP producer.

Ссылки

Пакеты

Наименование

org.apache.camel:camel-core

maven
Затронутые версииВерсия исправления

< 2.9.7

2.9.7

Наименование

org.apache.camel:camel-core

maven
Затронутые версииВерсия исправления

>= 2.10.0, < 2.10.7

2.10.7

Наименование

org.apache.camel:camel-core

maven
Затронутые версииВерсия исправления

>= 2.11.0, < 2.11.2

2.11.2

Наименование

org.apache.camel:camel-core

maven
Затронутые версииВерсия исправления

= 2.12.0

2.12.1

EPSS

Процентиль: 95%
0.08523
Низкий

Дефекты

CWE-94

Связанные уязвимости

redhat
почти 13 лет назад

Apache Camel before 2.9.7, 2.10.0 before 2.10.7, 2.11.0 before 2.11.2, and 2.12.0 allows remote attackers to execute arbitrary simple language expressions by including "$simple{}" in a CamelFileName message header to a (1) FILE or (2) FTP producer.

nvd
почти 13 лет назад

Apache Camel before 2.9.7, 2.10.0 before 2.10.7, 2.11.0 before 2.11.2, and 2.12.0 allows remote attackers to execute arbitrary simple language expressions by including "$simple{}" in a CamelFileName message header to a (1) FILE or (2) FTP producer.

EPSS

Процентиль: 95%
0.08523
Низкий

Дефекты

CWE-94