CVE-2017-3159
- EPSS 2.77%
- Veröffentlicht 07.03.2017 15:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Apache Camel's camel-snakeyaml component is vulnerable to Java object de-serialization vulnerability. De-serializing untrusted data can lead to security flaws.
CVE-2015-5348
- EPSS 6.83%
- Veröffentlicht 15.04.2016 15:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Apache Camel 2.6.x through 2.14.x, 2.15.x before 2.15.5, and 2.16.x before 2.16.1, when using (1) camel-jetty or (2) camel-servlet as a consumer in Camel routes, allow remote attackers to execute arbitrary commands via a crafted serialized Java objec...
CVE-2015-5344
- EPSS 4.97%
- Veröffentlicht 03.02.2016 18:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The camel-xstream component in Apache Camel before 2.15.5 and 2.16.x before 2.16.1 allow remote attackers to execute arbitrary commands via a crafted serialized Java object in an HTTP request.
- EPSS 2.02%
- Veröffentlicht 03.06.2015 20:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple XML external entity (XXE) vulnerabilities in builder/xml/XPathBuilder.java in Apache Camel before 2.13.4 and 2.14.x before 2.14.2 allow remote attackers to read arbitrary files via an external entity in an invalid XML (1) String or (2) Gener...
- EPSS 3.62%
- Veröffentlicht 03.06.2015 20:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
XML external entity (XXE) vulnerability in the XML converter setup in converter/jaxp/XmlConverter.java in Apache Camel before 2.13.4 and 2.14.x before 2.14.2 allows remote attackers to read arbitrary files via an external entity in an SAXSource.
CVE-2014-0003
- EPSS 28.97%
- Veröffentlicht 21.03.2014 04:38:59
- Zuletzt bearbeitet 12.04.2025 10:46:40
The XSLT component in Apache Camel 2.11.x before 2.11.4, 2.12.x before 2.12.3, and possibly earlier versions allows remote attackers to execute arbitrary Java methods via a crafted message.
CVE-2014-0002
- EPSS 28.74%
- Veröffentlicht 21.03.2014 04:38:59
- Zuletzt bearbeitet 12.04.2025 10:46:40
The XSLT component in Apache Camel before 2.11.4 and 2.12.x before 2.12.3 allows remote attackers to read arbitrary files and possibly have other unspecified impact via an XML document containing an external entity declaration in conjunction with an ...
CVE-2013-4330
- EPSS 26.19%
- Veröffentlicht 04.10.2013 17:55:09
- Zuletzt bearbeitet 11.04.2025 00:51:21
Apache Camel before 2.9.7, 2.10.0 before 2.10.7, 2.11.0 before 2.11.2, and 2.12.0 allows remote attackers to execute arbitrary simple language expressions by including "$simple{}" in a CamelFileName message header to a (1) FILE or (2) FTP producer.