cbcvebase.
CVE-2020-11994
published 2020-07-08

CVE-2020-11994: Server-Side Template Injection and arbitrary file disclosure on Camel templating components

high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
Server-Side Template Injection and arbitrary file disclosure on Camel templating components

Affected

10 ranges
VendorProductVersion rangeFixed in
apachecamel
apachecamel
apachecamel
apachecamel2.22.0 – 2.22.5
apachecamel2.23.0 – 2.23.4
apachecamel2.24.0 – 2.24.3
apachecamel3.0.0 – 3.3.0
oraclecommunications_diameter_signaling_router8.0.0 – 8.5.0
oracleenterprise_manager_base_platform
oracleenterprise_repository