Описание
Apache Camel before 2.9.7, 2.10.0 before 2.10.7, 2.11.0 before 2.11.2, and 2.12.0 allows remote attackers to execute arbitrary simple language expressions by including "$simple{}" in a CamelFileName message header to a (1) FILE or (2) FTP producer.
Дополнительная информация
Статус:
Important
https://bugzilla.redhat.com/show_bug.cgi?id=1011726Camel: remote code execution via header field manipulation
EPSS
Процентиль: 95%
0.08523
Низкий
6.8 Medium
CVSS2
Связанные уязвимости
nvd
почти 13 лет назад
Apache Camel before 2.9.7, 2.10.0 before 2.10.7, 2.11.0 before 2.11.2, and 2.12.0 allows remote attackers to execute arbitrary simple language expressions by including "$simple{}" in a CamelFileName message header to a (1) FILE or (2) FTP producer.
EPSS
Процентиль: 95%
0.08523
Низкий
6.8 Medium
CVSS2