CVE-2013-4330

Apache Camel before 2.9.7, 2.10.0 before 2.10.7, 2.11.0 before 2.11.2, and 2.12.0 allows remote attackers to execute arbitrary simple language expressions by including "$simple{}" in a CamelFileName message header to a (1) FILE or (2) FTP producer.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 95%
VendorProductVersion
apachecamel
𝑥
≤ 2.9.6
apachecamel
1.0.0
apachecamel
1.1.0
apachecamel
1.2.0
apachecamel
1.3.0
apachecamel
1.4.0
apachecamel
1.5.0
apachecamel
1.6.0
apachecamel
1.6.1
apachecamel
1.6.2
apachecamel
1.6.3
apachecamel
1.6.4
apachecamel
2.0.0
apachecamel
2.0.0:milestone1
apachecamel
2.0.0:milestone2
apachecamel
2.0.0:milestone3
apachecamel
2.1.0
apachecamel
2.2.0
apachecamel
2.3.0
apachecamel
2.4.0
apachecamel
2.5.0
apachecamel
2.6.0
apachecamel
2.7.0
apachecamel
2.7.1
apachecamel
2.7.2
apachecamel
2.7.3
apachecamel
2.7.4
apachecamel
2.7.5
apachecamel
2.8.0
apachecamel
2.8.1
apachecamel
2.8.2
apachecamel
2.8.3
apachecamel
2.8.4
apachecamel
2.8.5
apachecamel
2.8.6
apachecamel
2.9.0
apachecamel
2.9.1
apachecamel
2.9.2
apachecamel
2.9.3
apachecamel
2.9.4
apachecamel
2.9.5
apachecamel
2.10.0
apachecamel
2.10.1
apachecamel
2.10.2
apachecamel
2.10.3
apachecamel
2.10.4
apachecamel
2.10.5
apachecamel
2.10.6
apachecamel
2.11.0
apachecamel
2.11.1
apachecamel
2.12.0
𝑥
= Vulnerable software versions
References