Apache

Camel

28 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 2.05%
  • Published 14.05.2020 17:15:12
  • Last modified 21.11.2024 04:59:00

Apache Camel's JMX is vulnerable to Rebind Flaw. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.x, 3.0.0 up to 3.1.0 is affected. Users should upgrade to 3.2.0.

  • EPSS 2.09%
  • Published 11.02.2020 12:15:21
  • Last modified 21.11.2024 05:34:13

HtmlUnit prior to 2.37.0 contains code execution vulnerabilities. HtmlUnit initializes Rhino engine improperly, hence a malicious JavScript code can execute arbitrary Java code on the application. Moreover, when embedded in Android application, Andro...

  • EPSS 2.24%
  • Published 28.05.2019 19:29:02
  • Last modified 21.11.2024 04:16:26

Apache Camel prior to 2.24.0 contains an XML external entity injection (XXE) vulnerability (CWE-611) due to using an outdated vulnerable JSON-lib library. This affects only the camel-xmljson component, which was removed.

Exploit
  • EPSS 2.37%
  • Published 30.04.2019 22:29:00
  • Last modified 21.11.2024 04:16:27

Apache Camel's File is vulnerable to directory traversal. Camel 2.21.0 to 2.21.3, 2.22.0 to 2.22.2, 2.23.0 and the unsupported Camel 2.x (2.19 and earlier) versions may be also affected.

  • EPSS 2.47%
  • Published 17.09.2018 14:29:00
  • Last modified 21.11.2024 04:13:09

Apache Camel's Mail 2.20.0 through 2.20.3, 2.21.0 through 2.21.1 and 2.22.0 is vulnerable to path traversal.

  • EPSS 2.97%
  • Published 31.07.2018 13:29:00
  • Last modified 21.11.2024 04:13:07

Apache Camel 2.20.0 to 2.20.3 and 2.21.0 Core is vulnerable to XXE in XSD validation processor.

  • EPSS 4.57%
  • Published 15.11.2017 15:29:00
  • Last modified 20.04.2025 01:37:25

The camel-castor component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability. De-serializing untrusted data can lead to security flaws.

  • EPSS 3.41%
  • Published 15.11.2017 15:29:00
  • Last modified 20.04.2025 01:37:25

The camel-hessian component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability. De-serializing untrusted data can lead to security flaws.

Exploit
  • EPSS 7.39%
  • Published 28.03.2017 18:59:00
  • Last modified 20.04.2025 01:37:25

Apache Camel's Jackson and JacksonXML unmarshalling operation are vulnerable to Remote Code Execution attacks.

  • EPSS 0.72%
  • Published 16.03.2017 15:59:00
  • Last modified 20.04.2025 01:37:25

Apache Camel's Validation Component is vulnerable against SSRF via remote DTDs and XXE.