Apache

Camel

28 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 2.77%
  • Published 07.03.2017 15:59:00
  • Last modified 20.04.2025 01:37:25

Apache Camel's camel-snakeyaml component is vulnerable to Java object de-serialization vulnerability. De-serializing untrusted data can lead to security flaws.

  • EPSS 6.83%
  • Published 15.04.2016 15:59:00
  • Last modified 12.04.2025 10:46:40

Apache Camel 2.6.x through 2.14.x, 2.15.x before 2.15.5, and 2.16.x before 2.16.1, when using (1) camel-jetty or (2) camel-servlet as a consumer in Camel routes, allow remote attackers to execute arbitrary commands via a crafted serialized Java objec...

  • EPSS 4.97%
  • Published 03.02.2016 18:59:00
  • Last modified 12.04.2025 10:46:40

The camel-xstream component in Apache Camel before 2.15.5 and 2.16.x before 2.16.1 allow remote attackers to execute arbitrary commands via a crafted serialized Java object in an HTTP request.

  • EPSS 2.02%
  • Published 03.06.2015 20:59:04
  • Last modified 12.04.2025 10:46:40

Multiple XML external entity (XXE) vulnerabilities in builder/xml/XPathBuilder.java in Apache Camel before 2.13.4 and 2.14.x before 2.14.2 allow remote attackers to read arbitrary files via an external entity in an invalid XML (1) String or (2) Gener...

  • EPSS 3.62%
  • Published 03.06.2015 20:59:02
  • Last modified 12.04.2025 10:46:40

XML external entity (XXE) vulnerability in the XML converter setup in converter/jaxp/XmlConverter.java in Apache Camel before 2.13.4 and 2.14.x before 2.14.2 allows remote attackers to read arbitrary files via an external entity in an SAXSource.

Exploit
  • EPSS 28.97%
  • Published 21.03.2014 04:38:59
  • Last modified 12.04.2025 10:46:40

The XSLT component in Apache Camel 2.11.x before 2.11.4, 2.12.x before 2.12.3, and possibly earlier versions allows remote attackers to execute arbitrary Java methods via a crafted message.

Exploit
  • EPSS 28.74%
  • Published 21.03.2014 04:38:59
  • Last modified 12.04.2025 10:46:40

The XSLT component in Apache Camel before 2.11.4 and 2.12.x before 2.12.3 allows remote attackers to read arbitrary files and possibly have other unspecified impact via an XML document containing an external entity declaration in conjunction with an ...

  • EPSS 26.19%
  • Published 04.10.2013 17:55:09
  • Last modified 11.04.2025 00:51:21

Apache Camel before 2.9.7, 2.10.0 before 2.10.7, 2.11.0 before 2.11.2, and 2.12.0 allows remote attackers to execute arbitrary simple language expressions by including "$simple{}" in a CamelFileName message header to a (1) FILE or (2) FTP producer.