CVE-2013-4330
published 2013-10-04CVE-2013-4330: Apache Camel before 2.9.7, 2.10.0 before 2.10.7, 2.11.0 before 2.11.2, and 2.12.0 allows remote attackers to execute arbitrary simple language expressions by…
PriorityP346medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
8.52%
94.4th percentile
Apache Camel before 2.9.7, 2.10.0 before 2.10.7, 2.11.0 before 2.11.2, and 2.12.0 allows remote attackers to execute arbitrary simple language expressions by including "$simple{}" in a CamelFileName message header to a (1) FILE or (2) FTP producer.
Affected
50 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | camel | <= 2.9.6 | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_apache6.8CRITICAL
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Camel: remote code execution via header field manipulation
vendor_redhat·2013-09-30·CVSS 6.8
CVE-2013-4330 [MEDIUM] Camel: remote code execution via header field manipulation
Camel: remote code execution via header field manipulation
Apache Camel before 2.9.7, 2.10.0 before 2.10.7, 2.11.0 before 2.11.2, and 2.12.0 allows remote attackers to execute arbitrary simple language expressions by including "$simple{}" in a CamelFileName message header to a (1) FILE or (2) FTP producer.
Apache
Apache camel: CVE-2013-4330
vendor_apache·CVSS 6.8
CVE-2013-4330 [CRITICAL] Apache camel: CVE-2013-4330
Apache camel: CVE-2013-4330
2.9.0 up to 2.9.7, 2.10.0 up to 2.10.6, 2.11.0 up to 2.11.1, 2.12.0 2.9.8, 2.10.7, 2.11.2, 2.12.1 and newer CRITICAL Writing files using FILE or FTP components, can potentially be exploited by a malicious user. Edit this Page Back to top
Severity: critical
GHSA
Improper Control of Generation of Code in Apache Camel
ghsa·2022-05-13
CVE-2013-4330 [MEDIUM] CWE-94 Improper Control of Generation of Code in Apache Camel
Improper Control of Generation of Code in Apache Camel
Apache Camel before 2.9.7, 2.10.0 before 2.10.7, 2.11.0 before 2.11.2, and 2.12.0 allows remote attackers to execute arbitrary simple language expressions by including "$simple{}" in a CamelFileName message header to a (1) FILE or (2) FTP producer.
OSV
Improper Control of Generation of Code in Apache Camel
osv·2022-05-13
CVE-2013-4330 [MEDIUM] Improper Control of Generation of Code in Apache Camel
Improper Control of Generation of Code in Apache Camel
Apache Camel before 2.9.7, 2.10.0 before 2.10.7, 2.11.0 before 2.11.2, and 2.12.0 allows remote attackers to execute arbitrary simple language expressions by including "$simple{}" in a CamelFileName message header to a (1) FILE or (2) FTP producer.
OSV
perl vulnerabilities
osv·2016-03-02·CVSS 7.5
CVE-2013-7422 perl vulnerabilities
perl vulnerabilities
It was discovered that Perl incorrectly handled certain regular expressions
with an invalid backreference. An attacker could use this issue to cause
Perl to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2013-7422)
Markus Vervier discovered that Perl incorrectly handled nesting in the
Data::Dumper module. An attacker could use this issue to cause Perl to
consume memory and crash, resulting in a denial of service. (CVE-2014-4330)
Stephane Chazelas discovered that Perl incorrectly handled duplicate
environment variables. An attacker could possibly use this issue to bypass
the taint protection mechanism. (CVE-2016-2381)
No detection rules found.
No public exploits indexed.
http://camel.apache.org/security-advisories.data/CVE-2013-4330.txt.asc?version=1&modificationDate=1380535446943http://osvdb.org/97941http://packetstormsecurity.com/files/123454/http://rhn.redhat.com/errata/RHSA-2013-1862.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0124.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0140.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0245.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0254.htmlhttp://seclists.org/fulldisclosure/2013/Sep/178http://secunia.com/advisories/54888https://exchange.xforce.ibmcloud.com/vulnerabilities/87542https://lists.apache.org/thread.html/2318d7f7d87724d8716cd650c21b31cb06e4d34f6d0f5ee42f28fdaf%40%3Ccommits.camel.apache.org%3Ehttps://lists.apache.org/thread.html/b4014ea7c5830ca1fc28edd5cafedfe93ad4af2d9e69c961c5def31d%40%3Ccommits.camel.apache.org%3Ehttp://camel.apache.org/security-advisories.data/CVE-2013-4330.txt.asc?version=1&modificationDate=1380535446943http://osvdb.org/97941http://packetstormsecurity.com/files/123454/http://rhn.redhat.com/errata/RHSA-2013-1862.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0124.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0140.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0245.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0254.htmlhttp://seclists.org/fulldisclosure/2013/Sep/178http://secunia.com/advisories/54888https://exchange.xforce.ibmcloud.com/vulnerabilities/87542https://lists.apache.org/thread.html/2318d7f7d87724d8716cd650c21b31cb06e4d34f6d0f5ee42f28fdaf%40%3Ccommits.camel.apache.org%3Ehttps://lists.apache.org/thread.html/b4014ea7c5830ca1fc28edd5cafedfe93ad4af2d9e69c961c5def31d%40%3Ccommits.camel.apache.org%3E
2013-10-04
Published