CVE-2013-4330

EUVD-2022-5751
Apache Camel before 2.9.7, 2.10.0 before 2.10.7, 2.11.0 before 2.11.2, and 2.12.0 allows remote attackers to execute arbitrary simple language expressions by including "$simple{}" in a CamelFileName message header to a (1) FILE or (2) FTP producer.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 95%
Affected Products (NVD)
VendorProductVersion
apachecamel
𝑥
≤ 2.9.6
apachecamel
1.0.0
apachecamel
1.1.0
apachecamel
1.2.0
apachecamel
1.3.0
apachecamel
1.4.0
apachecamel
1.5.0
apachecamel
1.6.0
apachecamel
1.6.1
apachecamel
1.6.2
apachecamel
1.6.3
apachecamel
1.6.4
apachecamel
2.0.0
apachecamel
2.0.0:milestone1
apachecamel
2.0.0:milestone2
apachecamel
2.0.0:milestone3
apachecamel
2.1.0
apachecamel
2.2.0
apachecamel
2.3.0
apachecamel
2.4.0
apachecamel
2.5.0
apachecamel
2.6.0
apachecamel
2.7.0
apachecamel
2.7.1
apachecamel
2.7.2
apachecamel
2.7.3
apachecamel
2.7.4
apachecamel
2.7.5
apachecamel
2.8.0
apachecamel
2.8.1
apachecamel
2.8.2
apachecamel
2.8.3
apachecamel
2.8.4
apachecamel
2.8.5
apachecamel
2.8.6
apachecamel
2.9.0
apachecamel
2.9.1
apachecamel
2.9.2
apachecamel
2.9.3
apachecamel
2.9.4
apachecamel
2.9.5
apachecamel
2.10.0
apachecamel
2.10.1
apachecamel
2.10.2
apachecamel
2.10.3
apachecamel
2.10.4
apachecamel
2.10.5
apachecamel
2.10.6
apachecamel
2.11.0
apachecamel
2.11.1
apachecamel
2.12.0
𝑥
= Vulnerable software versions
References