Server-Side Template Injection Vulnerability in Apache Camel Components
CVE-2020-11994
7.5HIGH
Summary
This vulnerability allows attackers to exploit the Camel templating components, resulting in server-side template injection. By manipulating the templates, an attacker can execute arbitrary code or access sensitive files on the server, posing significant security risks to applications using affected versions of Apache Camel. Developers and administrators must ensure they are using the latest secure versions to mitigate this exposure.
Affected Version(s)
Apache Camel Camel 2.25.0 to 2.25.1, Camel 3.0.0 to 3.3.0. The unsupported Camel 2.x (2.24 and earlier) versions may be also affected.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved