Remote Command Execution Vulnerability in Apache Camel by Apache
CVE-2015-5348
8.1HIGH
Summary
A vulnerability in Apache Camel allows remote attackers to execute arbitrary commands by crafting a serialized Java object sent through an HTTP request, particularly when using camel-jetty or camel-servlet as consumers in Camel routes. This issue affects multiple versions of Apache Camel, making it crucial for users to apply patches and updates promptly to safeguard their applications.
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved