CVE-2019-0194
published 2019-04-30CVE-2019-0194: Apache Camel's File is vulnerable to directory traversal. Camel 2.21.0 to 2.21.3, 2.22.0 to 2.22.2, 2.23.0 and the unsupported Camel 2.x (2.19 and earlier)…
PriorityP349high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
8.48%
94.4th percentile
Apache Camel's File is vulnerable to directory traversal. Camel 2.21.0 to 2.21.3, 2.22.0 to 2.22.2, 2.23.0 and the unsupported Camel 2.x (2.19 and earlier) versions may be also affected.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | apache_camel | — | — |
| apache | apache_camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | 2.0.0 – 2.19.0 | — |
| apache | camel | 2.21.0 – 2.21.3 | — |
| apache | camel | 2.22.0 – 2.22.2 | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_apache7.5MEDIUM
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Path Traversal in Apache Camel
osv·2019-05-02
CVE-2019-0194 [HIGH] Path Traversal in Apache Camel
Path Traversal in Apache Camel
Apache Camel's File is vulnerable to directory traversal. Camel 2.21.0 to 2.21.3, 2.22.0 to 2.22.2, 2.23.0 and the unsupported Camel 2.x (2.19 and earlier) versions may be also affected.
GHSA
Path Traversal in Apache Camel
ghsa·2019-05-02
CVE-2019-0194 [HIGH] CWE-22 Path Traversal in Apache Camel
Path Traversal in Apache Camel
Apache Camel's File is vulnerable to directory traversal. Camel 2.21.0 to 2.21.3, 2.22.0 to 2.22.2, 2.23.0 and the unsupported Camel 2.x (2.19 and earlier) versions may be also affected.
Red Hat
camel: Directory traversal in file producer
vendor_redhat·2019-04-30·CVSS 7.5
CVE-2019-0194 [HIGH] CWE-22 camel: Directory traversal in file producer
camel: Directory traversal in file producer
Apache Camel's File is vulnerable to directory traversal. Camel 2.21.0 to 2.21.3, 2.22.0 to 2.22.2, 2.23.0 and the unsupported Camel 2.x (2.19 and earlier) versions may be also affected.
Package: camel-core (Red Hat Fuse 7) - Affected
Package: camel-core (Red Hat JBoss A-MQ 6) - Out of support scope
Package: camel-core (Red Hat JBoss BRMS 5) - Out of support scope
Package: camel-core (Red Hat JBoss BRMS 6) - Out of support scope
Package: camel-core (Red Hat JBoss Data Grid 7) - Not affected
Package: camel-core (Red Hat JBoss Fuse 6) - Out of support scope
Package: camel-core (Red Hat JBoss Fuse Service Works 6) - Out of support scope
Package: camel-core (Red Hat JBoss SOA Platform 5) - Out of support scope
Apache
Apache camel: CVE-2019-0194
vendor_apache·CVSS 7.5
CVE-2019-0194 [MEDIUM] Apache camel: CVE-2019-0194
Apache camel: CVE-2019-0194
2.21.0 up to 2.21.3, 2.22.0 up to 2.22.2, 2.23.0 2.21.5, 2.22.3, 2.23.1 MEDIUM Apache Camel's File is vulnerable to directory traversal 2018
Severity: medium
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2019/04/30/2http://www.securityfocus.com/bid/108181https://lists.apache.org/thread.html/0a163d02169d3d361150e8183df4af33f1a3d8a419b2937ac8e6c66f%40%3Cusers.camel.apache.org%3Ehttps://lists.apache.org/thread.html/0cb842f367336b352a7548e290116b64b78b8e7b99402deaba81a687%40%3Ccommits.camel.apache.org%3Ehttps://lists.apache.org/thread.html/2318d7f7d87724d8716cd650c21b31cb06e4d34f6d0f5ee42f28fdaf%40%3Ccommits.camel.apache.org%3Ehttps://lists.apache.org/thread.html/45e23ade8d3cb754615f95975e89e8dc73c59eeac914f07d53acbac6%40%3Ccommits.camel.apache.org%3Ehttps://lists.apache.org/thread.html/9a6bc022f7ab28e4894b1831ce336eb41ae6d5c24d86646fe16e956f%40%3Ccommits.camel.apache.org%3Ehttps://lists.apache.org/thread.html/a39441db574ee996f829344491b3211b53c9ed926f00ae5d88943b76%40%3Cdev.camel.apache.org%3Ehttps://lists.apache.org/thread.html/b4014ea7c5830ca1fc28edd5cafedfe93ad4af2d9e69c961c5def31d%40%3Ccommits.camel.apache.org%3Ehttp://www.openwall.com/lists/oss-security/2019/04/30/2http://www.securityfocus.com/bid/108181https://lists.apache.org/thread.html/0a163d02169d3d361150e8183df4af33f1a3d8a419b2937ac8e6c66f%40%3Cusers.camel.apache.org%3Ehttps://lists.apache.org/thread.html/0cb842f367336b352a7548e290116b64b78b8e7b99402deaba81a687%40%3Ccommits.camel.apache.org%3Ehttps://lists.apache.org/thread.html/2318d7f7d87724d8716cd650c21b31cb06e4d34f6d0f5ee42f28fdaf%40%3Ccommits.camel.apache.org%3Ehttps://lists.apache.org/thread.html/45e23ade8d3cb754615f95975e89e8dc73c59eeac914f07d53acbac6%40%3Ccommits.camel.apache.org%3Ehttps://lists.apache.org/thread.html/9a6bc022f7ab28e4894b1831ce336eb41ae6d5c24d86646fe16e956f%40%3Ccommits.camel.apache.org%3Ehttps://lists.apache.org/thread.html/a39441db574ee996f829344491b3211b53c9ed926f00ae5d88943b76%40%3Cdev.camel.apache.org%3Ehttps://lists.apache.org/thread.html/b4014ea7c5830ca1fc28edd5cafedfe93ad4af2d9e69c961c5def31d%40%3Ccommits.camel.apache.org%3E
2019-04-30
Published