CVE-2013-4330

Apache Camel before 2.9.7, 2.10.0 before 2.10.7, 2.11.0 before 2.11.2, and 2.12.0 allows remote attackers to execute arbitrary simple language expressions by including "$simple{}" in a CamelFileName message header to a (1) FILE or (2) FTP producer.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
apachecamel
𝑥
≤ 2.9.6
apachecamel
1.0.0
apachecamel
1.1.0
apachecamel
1.2.0
apachecamel
1.3.0
apachecamel
1.4.0
apachecamel
1.5.0
apachecamel
1.6.0
apachecamel
1.6.1
apachecamel
1.6.2
apachecamel
1.6.3
apachecamel
1.6.4
apachecamel
2.0.0
apachecamel
2.0.0:milestone1
apachecamel
2.0.0:milestone2
apachecamel
2.0.0:milestone3
apachecamel
2.1.0
apachecamel
2.2.0
apachecamel
2.3.0
apachecamel
2.4.0
apachecamel
2.5.0
apachecamel
2.6.0
apachecamel
2.7.0
apachecamel
2.7.1
apachecamel
2.7.2
apachecamel
2.7.3
apachecamel
2.7.4
apachecamel
2.7.5
apachecamel
2.8.0
apachecamel
2.8.1
apachecamel
2.8.2
apachecamel
2.8.3
apachecamel
2.8.4
apachecamel
2.8.5
apachecamel
2.8.6
apachecamel
2.9.0
apachecamel
2.9.1
apachecamel
2.9.2
apachecamel
2.9.3
apachecamel
2.9.4
apachecamel
2.9.5
apachecamel
2.10.0
apachecamel
2.10.1
apachecamel
2.10.2
apachecamel
2.10.3
apachecamel
2.10.4
apachecamel
2.10.5
apachecamel
2.10.6
apachecamel
2.11.0
apachecamel
2.11.1
apachecamel
2.12.0
𝑥
= Vulnerable software versions
References