CVE-2018-8041
published 2018-09-17CVE-2018-8041: Apache Camel's Mail 2.20.0 through 2.20.3, 2.21.0 through 2.21.1 and 2.22.0 is vulnerable to path traversal.
PriorityP434medium5.3CVSS 3.0
AVNACLPRNUINSUCLINAN
EPSS
9.85%
95.0th percentile
Apache Camel's Mail 2.20.0 through 2.20.3, 2.21.0 through 2.21.1 and 2.22.0 is vulnerable to path traversal.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | 2.20.0 – 2.20.3 | — |
| apache | camel | 2.21.0 – 2.21.1 | — |
| apache_software_foundation | apache_camel | — | — |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_apache5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Apache Camel's Mail is vulnerable to path traversal
ghsa·2018-10-16
CVE-2018-8041 [MEDIUM] CWE-22 Apache Camel's Mail is vulnerable to path traversal
Apache Camel's Mail is vulnerable to path traversal
Apache Camel's Mail 2.20.0 through 2.20.3, 2.21.0 through 2.21.1 and 2.22.0 is vulnerable to path traversal.
OSV
Apache Camel's Mail is vulnerable to path traversal
osv·2018-10-16
CVE-2018-8041 [MEDIUM] Apache Camel's Mail is vulnerable to path traversal
Apache Camel's Mail is vulnerable to path traversal
Apache Camel's Mail 2.20.0 through 2.20.3, 2.21.0 through 2.21.1 and 2.22.0 is vulnerable to path traversal.
Red Hat
camel-mail: path traversal vulnerability
vendor_redhat·2018-06-09·CVSS 5.3
CVE-2018-8041 [MEDIUM] CWE-22 camel-mail: path traversal vulnerability
camel-mail: path traversal vulnerability
Apache Camel's Mail 2.20.0 through 2.20.3, 2.21.0 through 2.21.1 and 2.22.0 is vulnerable to path traversal.
Package: switchyard (Red Hat JBoss Data Virtualization 6) - Will not fix
Package: camel (Red Hat JBoss Fuse 6) - Will not fix
Package: camel (Red Hat JBoss Fuse Service Works 6) - Will not fix
Apache
Apache camel: CVE-2018-8041
vendor_apache·CVSS 5.3
CVE-2018-8041 [MEDIUM] Apache camel: CVE-2018-8041
Apache camel: CVE-2018-8041
2.20.0 up to 2.20.3, 2.21.0 up to 2.21.1, 2.22.0 2.20.4, 2.21.1, 2.22.1 and newer MEDIUM Apache Camel's Mail is vulnerable to path traversal
Severity: medium
No detection rules found.
No public exploits indexed.
http://camel.apache.org/security-advisories.data/CVE-2018-8041.txt.asc?version=1&modificationDate=1536746339000&api=v2http://www.securityfocus.com/bid/105352https://access.redhat.com/errata/RHSA-2018:3768https://issues.apache.org/jira/browse/CAMEL-12630https://lists.apache.org/thread.html/2318d7f7d87724d8716cd650c21b31cb06e4d34f6d0f5ee42f28fdaf%40%3Ccommits.camel.apache.org%3Ehttps://lists.apache.org/thread.html/b4014ea7c5830ca1fc28edd5cafedfe93ad4af2d9e69c961c5def31d%40%3Ccommits.camel.apache.org%3Ehttp://camel.apache.org/security-advisories.data/CVE-2018-8041.txt.asc?version=1&modificationDate=1536746339000&api=v2http://www.securityfocus.com/bid/105352https://access.redhat.com/errata/RHSA-2018:3768https://issues.apache.org/jira/browse/CAMEL-12630https://lists.apache.org/thread.html/2318d7f7d87724d8716cd650c21b31cb06e4d34f6d0f5ee42f28fdaf%40%3Ccommits.camel.apache.org%3Ehttps://lists.apache.org/thread.html/b4014ea7c5830ca1fc28edd5cafedfe93ad4af2d9e69c961c5def31d%40%3Ccommits.camel.apache.org%3E
2018-09-17
Published