cbcvebase.
CVE-2013-4330
published 2013-10-04

CVE-2013-4330: Apache Camel before 2.9.7, 2.10.0 before 2.10.7, 2.11.0 before 2.11.2, and 2.12.0 allows remote attackers to execute arbitrary simple language expressions by…

PriorityP346medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
8.52%
94.4th percentile
Apache Camel before 2.9.7, 2.10.0 before 2.10.7, 2.11.0 before 2.11.2, and 2.12.0 allows remote attackers to execute arbitrary simple language expressions by including "$simple{}" in a CamelFileName message header to a (1) FILE or (2) FTP producer.

Affected

50 ranges· showing 25
VendorProductVersion rangeFixed in
apachecamel<= 2.9.6
apachecamel
apachecamel
apachecamel
apachecamel
apachecamel
apachecamel
apachecamel
apachecamel
apachecamel
apachecamel
apachecamel
apachecamel
apachecamel
apachecamel
apachecamel
apachecamel
apachecamel
apachecamel
apachecamel
apachecamel
apachecamel
apachecamel
apachecamel
apachecamel

CVSS provenance

nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_apache6.8CRITICAL
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.