Show filters
63 Total Results
Displaying 41-50 of 63
Sort by:
Attacker Value
Unknown
CVE-2020-11972
Disclosure Date: May 14, 2020 (last updated February 21, 2025)
Apache Camel RabbitMQ enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0.
0
Attacker Value
Unknown
CVE-2020-11973
Disclosure Date: May 14, 2020 (last updated February 21, 2025)
Apache Camel Netty enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0.
0
Attacker Value
Unknown
CVE-2020-11971
Disclosure Date: May 14, 2020 (last updated November 08, 2023)
Apache Camel's JMX is vulnerable to Rebind Flaw. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.x, 3.0.0 up to 3.1.0 is affected. Users should upgrade to 3.2.0.
0
Attacker Value
Unknown
CVE-2020-5529
Disclosure Date: February 11, 2020 (last updated February 21, 2025)
HtmlUnit prior to 2.37.0 contains code execution vulnerabilities. HtmlUnit initializes Rhino engine improperly, hence a malicious JavScript code can execute arbitrary Java code on the application. Moreover, when embedded in Android application, Android-specific initialization of Rhino engine is done in an improper way, hence a malicious JavaScript code can execute arbitrary Java code on the application.
0
Attacker Value
Unknown
CVE-2019-0188
Disclosure Date: May 28, 2019 (last updated November 08, 2023)
Apache Camel prior to 2.24.0 contains an XML external entity injection (XXE) vulnerability (CWE-611) due to using an outdated vulnerable JSON-lib library. This affects only the camel-xmljson component, which was removed.
0
Attacker Value
Unknown
CVE-2019-0194
Disclosure Date: April 30, 2019 (last updated November 08, 2023)
Apache Camel's File is vulnerable to directory traversal. Camel 2.21.0 to 2.21.3, 2.22.0 to 2.22.2, 2.23.0 and the unsupported Camel 2.x (2.19 and earlier) versions may be also affected.
0
Attacker Value
Unknown
CVE-2018-8041
Disclosure Date: September 17, 2018 (last updated November 08, 2023)
Apache Camel's Mail 2.20.0 through 2.20.3, 2.21.0 through 2.21.1 and 2.22.0 is vulnerable to path traversal.
0
Attacker Value
Unknown
CVE-2018-8027
Disclosure Date: July 31, 2018 (last updated November 08, 2023)
Apache Camel 2.20.0 to 2.20.3 and 2.21.0 Core is vulnerable to XXE in XSD validation processor.
0
Attacker Value
Unknown
CVE-2017-16023
Disclosure Date: June 04, 2018 (last updated November 26, 2024)
Decamelize is used to convert a dash/dot/underscore/space separated string to camelCase. Decamelize 1.1.0 through 1.1.1 uses regular expressions to evaluate a string and takes unescaped separator values, which can be used to create a denial of service attack.
0
Attacker Value
Unknown
CVE-2017-12633
Disclosure Date: November 15, 2017 (last updated November 08, 2023)
The camel-hessian component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability. De-serializing untrusted data can lead to security flaws.
0