Server-Side Template Injection Vulnerability in Apache Camel Components
CVE-2020-11994

7.5HIGH

Key Information:

Vendor

Apache

Vendor
CVE Published:
8 July 2020

What is CVE-2020-11994?

This vulnerability allows attackers to exploit the Camel templating components, resulting in server-side template injection. By manipulating the templates, an attacker can execute arbitrary code or access sensitive files on the server, posing significant security risks to applications using affected versions of Apache Camel. Developers and administrators must ensure they are using the latest secure versions to mitigate this exposure.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Apache Camel Camel 2.25.0 to 2.25.1, Camel 3.0.0 to 3.3.0. The unsupported Camel 2.x (2.24 and earlier) versions may be also affected.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.