CVE-2015-5348
published 2016-04-15CVE-2015-5348: Apache Camel 2.6.x through 2.14.x, 2.15.x before 2.15.5, and 2.16.x before 2.16.1, when using (1) camel-jetty or (2) camel-servlet as a consumer in Camel…
PriorityP354high8.1CVSS 3.0
AVNACHPRNUINSUCHIHAH
EPSS
6.37%
92.9th percentile
Apache Camel 2.6.x through 2.14.x, 2.15.x before 2.15.5, and 2.16.x before 2.16.1, when using (1) camel-jetty or (2) camel-servlet as a consumer in Camel routes, allow remote attackers to execute arbitrary commands via a crafted serialized Java object in an HTTP request.
Affected
59 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
CVSS provenance
nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_apache8.1MEDIUM
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Apache Camel can allow remote attackers to execute arbitrary commands
osv·2018-10-16
CVE-2015-5348 [HIGH] Apache Camel can allow remote attackers to execute arbitrary commands
Apache Camel can allow remote attackers to execute arbitrary commands
Apache Camel 2.6.x through 2.14.x, 2.15.x before 2.15.5, and 2.16.x before 2.16.1, when using (1) camel-jetty or (2) camel-servlet as a consumer in Camel routes, allow remote attackers to execute arbitrary commands via a crafted serialized Java object in an HTTP request.
GHSA
Apache Camel can allow remote attackers to execute arbitrary commands
ghsa·2018-10-16
CVE-2015-5348 [HIGH] Apache Camel can allow remote attackers to execute arbitrary commands
Apache Camel can allow remote attackers to execute arbitrary commands
Apache Camel 2.6.x through 2.14.x, 2.15.x before 2.15.5, and 2.16.x before 2.16.1, when using (1) camel-jetty or (2) camel-servlet as a consumer in Camel routes, allow remote attackers to execute arbitrary commands via a crafted serialized Java object in an HTTP request.
Red Hat
Camel: Java object deserialisation in Jetty/Servlet
vendor_redhat·2015-12-17·CVSS 8.1
CVE-2015-5348 [HIGH] Camel: Java object deserialisation in Jetty/Servlet
Camel: Java object deserialisation in Jetty/Servlet
Apache Camel 2.6.x through 2.14.x, 2.15.x before 2.15.5, and 2.16.x before 2.16.1, when using (1) camel-jetty or (2) camel-servlet as a consumer in Camel routes, allow remote attackers to execute arbitrary commands via a crafted serialized Java object in an HTTP request.
It was found that Apache Camel's Jetty/Servlet usage is vulnerable to Java object de-serialisation vulnerability. If using camel-jetty, or camel-servlet as a consumer in Camel routes, then Camel will automatically de-serialize HTTP requests that uses the content-header: application/x-java-serialized-object.
Package: camel (OpenShift Enterprise 1) - Affected
Package: Camel (Red Hat BPM Suite 6) - Not affected
Package: Camel (Red Hat JBoss BRMS 6) - Not affected
Packa
Apache
Apache camel: CVE-2015-5348
vendor_apache·CVSS 8.1
CVE-2015-5348 [MEDIUM] Apache camel: CVE-2015-5348
Apache camel: CVE-2015-5348
2.15.0 up to 2.15.4, 2.16.0 2.15.5, 2.16.1 and newer MEDIUM Apache Camel's Jetty/Servlet usage is vulnerable to Java object de-serialisation vulnerability.
Severity: medium
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-5348 Camel: Java object deserialisation in Jetty/Servlet
bugzilla·2015-12-18·CVSS 8.1
CVE-2015-5348 [HIGH] CVE-2015-5348 Camel: Java object deserialisation in Jetty/Servlet
CVE-2015-5348 Camel: Java object deserialisation in Jetty/Servlet
A flaw was found in Apache Camel:
Apache Camel's Jetty/Servlet usage is vulnerable to Java object de-serialisation vulnerability
If using camel-jetty, or camel-servlet as a consumer in Camel routes, then Camel will automatic de-serialize HTTP requests that uses the content-header: application/x-java-serialized-object.
External References:
https://camel.apache.org/security-advisories.data/CVE-2015-5348.txt
Discussion:
Tracker for Fuse 6.2.1: https://issues.jboss.org/browse/ENTESB-4744
---
Tracker for A-MQ 6.2.1: https://issues.jboss.org/browse/ENTMQ-1464
---
CVE-2015-5348 is currently scheduled to be fixed in the Fuse 6.3 release. It is ranked as having moderate impact, so we feel it's not worthy of including in a
arXiv
A Manually-Curated Dataset of Fixes to Vulnerabilities of Open-Source Software
arxiv_fulltext·2019-03-19
A Manually-Curated Dataset of Fixes to Vulnerabilities of Open-Source Software
0
624
29
2
30
205
178
420
0
817
163
364
28
594
1282
594
0
0
624
466
7
205
862
1282
594
862
46
181
empty
empty
## Abstract
Advancing our understanding of software vulnerabilities, automating
their identification, the analysis of their impact, and ultimately their mitigation is
necessary to enable the development of software that is more secure.
While operating a vulnerability assessment tool that we developed and that is currently
used by hundreds of development units at SAP, we manually collected and curated a dataset
of vulnerabilities of open-source software and the commits fixing them. The data was obtained both
from the National Vulnerability Database (NVD) and from project-specific Web resources that we
monitor on a continuous basis.
From that data, we
http://camel.apache.org/security-advisories.data/CVE-2015-5348.txt.aschttp://packetstormsecurity.com/files/134946/Apache-Camel-Java-Object-Deserialization.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2035.htmlhttp://www.securityfocus.com/archive/1/537147/100/0/threadedhttp://www.securityfocus.com/bid/80696https://issues.apache.org/jira/browse/CAMEL-9309https://lists.apache.org/thread.html/2318d7f7d87724d8716cd650c21b31cb06e4d34f6d0f5ee42f28fdaf%40%3Ccommits.camel.apache.org%3Ehttps://lists.apache.org/thread.html/b4014ea7c5830ca1fc28edd5cafedfe93ad4af2d9e69c961c5def31d%40%3Ccommits.camel.apache.org%3Ehttp://camel.apache.org/security-advisories.data/CVE-2015-5348.txt.aschttp://packetstormsecurity.com/files/134946/Apache-Camel-Java-Object-Deserialization.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2035.htmlhttp://www.securityfocus.com/archive/1/537147/100/0/threadedhttp://www.securityfocus.com/bid/80696https://issues.apache.org/jira/browse/CAMEL-9309https://lists.apache.org/thread.html/2318d7f7d87724d8716cd650c21b31cb06e4d34f6d0f5ee42f28fdaf%40%3Ccommits.camel.apache.org%3Ehttps://lists.apache.org/thread.html/b4014ea7c5830ca1fc28edd5cafedfe93ad4af2d9e69c961c5def31d%40%3Ccommits.camel.apache.org%3E
2016-04-15
Published