CVE-2020-11971
- EPSS 2.05%
- Veröffentlicht 14.05.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 04:59:00
Apache Camel's JMX is vulnerable to Rebind Flaw. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.x, 3.0.0 up to 3.1.0 is affected. Users should upgrade to 3.2.0.
CVE-2020-5529
- EPSS 2.09%
- Veröffentlicht 11.02.2020 12:15:21
- Zuletzt bearbeitet 21.11.2024 05:34:13
HtmlUnit prior to 2.37.0 contains code execution vulnerabilities. HtmlUnit initializes Rhino engine improperly, hence a malicious JavScript code can execute arbitrary Java code on the application. Moreover, when embedded in Android application, Andro...
CVE-2019-0188
- EPSS 2.24%
- Veröffentlicht 28.05.2019 19:29:02
- Zuletzt bearbeitet 21.11.2024 04:16:26
Apache Camel prior to 2.24.0 contains an XML external entity injection (XXE) vulnerability (CWE-611) due to using an outdated vulnerable JSON-lib library. This affects only the camel-xmljson component, which was removed.
CVE-2019-0194
- EPSS 2.37%
- Veröffentlicht 30.04.2019 22:29:00
- Zuletzt bearbeitet 21.11.2024 04:16:27
Apache Camel's File is vulnerable to directory traversal. Camel 2.21.0 to 2.21.3, 2.22.0 to 2.22.2, 2.23.0 and the unsupported Camel 2.x (2.19 and earlier) versions may be also affected.
CVE-2018-8041
- EPSS 2.47%
- Veröffentlicht 17.09.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 04:13:09
Apache Camel's Mail 2.20.0 through 2.20.3, 2.21.0 through 2.21.1 and 2.22.0 is vulnerable to path traversal.
CVE-2018-8027
- EPSS 2.97%
- Veröffentlicht 31.07.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 04:13:07
Apache Camel 2.20.0 to 2.20.3 and 2.21.0 Core is vulnerable to XXE in XSD validation processor.
CVE-2017-12634
- EPSS 4.57%
- Veröffentlicht 15.11.2017 15:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The camel-castor component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability. De-serializing untrusted data can lead to security flaws.
CVE-2017-12633
- EPSS 3.41%
- Veröffentlicht 15.11.2017 15:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The camel-hessian component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability. De-serializing untrusted data can lead to security flaws.
CVE-2016-8749
- EPSS 7.39%
- Veröffentlicht 28.03.2017 18:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Apache Camel's Jackson and JacksonXML unmarshalling operation are vulnerable to Remote Code Execution attacks.
CVE-2017-5643
- EPSS 0.72%
- Veröffentlicht 16.03.2017 15:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Apache Camel's Validation Component is vulnerable against SSRF via remote DTDs and XXE.