CVE-2015-5348 – org.apache.camel:camel-http-common
Package
Manager: maven
Name: org.apache.camel:camel-http-common
Vulnerable Version: >=0 <2.15.5 || =2.16.0 || >=2.16.0 <2.16.1
Severity
Level: High
CVSS v3.1: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS: 0.06832 pctl0.90968
Details
Apache Camel can allow remote attackers to execute arbitrary commands Apache Camel 2.6.x through 2.14.x, 2.15.x before 2.15.5, and 2.16.x before 2.16.1, when using (1) camel-jetty or (2) camel-servlet as a consumer in Camel routes, allow remote attackers to execute arbitrary commands via a crafted serialized Java object in an HTTP request.
Metadata
Created: 2018-10-16T23:12:20Z
Modified: 2023-12-19T22:56:00Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-26v6-w6fw-rh94/GHSA-26v6-w6fw-rh94.json
CWE IDs: []
Alternative ID: GHSA-26v6-w6fw-rh94
Finding: F096
Auto approve: 1