CVE-2020-11971

Severity
7.5HIGH
EPSS
9.7%
top 7.07%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 14
Latest updateApr 15

Description

Apache Camel's JMX is vulnerable to Rebind Flaw. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.x, 3.0.0 up to 3.1.0 is affected. Users should upgrade to 3.2.0.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages9 packages

Mavenorg.apache.camel:camel< 3.2.0
NVDapache/camel2.22.03.1.0
CVEListV5apache_camelApache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0

Patches

🔴Vulnerability Details

3
GHSA
Improper Input Validation in Apache Camel2021-05-21
OSV
Improper Input Validation in Apache Camel2021-05-21
CVEList
CVE-2020-11971: Apache Camel's JMX is vulnerable to Rebind Flaw2020-05-14

📋Vendor Advisories

3
Oracle
Oracle Oracle Communications Risk Matrix: Mediation (Apache Camel) — CVE-2020-119712022-04-15
Red Hat
camel: DNS Rebinding in JMX Connector could result in remote command execution2020-05-14
Apache
Apache camel: CVE-2020-11971

💬Community

1
Bugzilla
CVE-2020-11971 camel: DNS Rebinding in JMX Connector could result in remote command execution2020-06-18
CVE-2020-11971 (HIGH CVSS 7.5) | Apache Camel's JMX is vulnerable to | cvebase.io