CVE-2020-11994
published 2020-07-08CVE-2020-11994: Server-Side Template Injection and arbitrary file disclosure on Camel templating components
PriorityP346high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
4.49%
90.4th percentile
Server-Side Template Injection and arbitrary file disclosure on Camel templating components
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | 2.22.0 – 2.22.5 | — |
| apache | camel | 2.23.0 – 2.23.4 | — |
| apache | camel | 2.24.0 – 2.24.3 | — |
| apache | camel | 3.0.0 – 3.3.0 | — |
| oracle | communications_diameter_signaling_router | 8.0.0 – 8.5.0 | — |
| oracle | enterprise_manager_base_platform | — | — |
| oracle | enterprise_repository | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_apache7.5MEDIUM
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Server side template injection in Apache Camel
osv·2020-07-29
CVE-2020-11994 [HIGH] Server side template injection in Apache Camel
Server side template injection in Apache Camel
Server-Side Template Injection and arbitrary file disclosure on Camel templating components
GHSA
Server side template injection in Apache Camel
ghsa·2020-07-29
CVE-2020-11994 [HIGH] CWE-74 Server side template injection in Apache Camel
Server side template injection in Apache Camel
Server-Side Template Injection and arbitrary file disclosure on Camel templating components
Oracle
Oracle Oracle Communications Risk Matrix: IDIH - Visualization (Apache Camel) — CVE-2020-11994
vendor_oracle·2021-10-15·CVSS 7.5
CVE-2020-11994 [HIGH] Oracle Oracle Communications Risk Matrix: IDIH - Visualization (Apache Camel) — CVE-2020-11994
Oracle Oracle Communications Risk Matrix: IDIH - Visualization (Apache Camel) vulnerability
CVE: CVE-2020-11994
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2021 (OCT 2021)
Oracle
Oracle Oracle Enterprise Manager Risk Matrix: Reporting Framework (Apache Camel) — CVE-2020-11994
vendor_oracle·2021-04-15·CVSS 7.5
CVE-2020-11994 [HIGH] Oracle Oracle Enterprise Manager Risk Matrix: Reporting Framework (Apache Camel) — CVE-2020-11994
Oracle Oracle Enterprise Manager Risk Matrix: Reporting Framework (Apache Camel) vulnerability
CVE: CVE-2020-11994
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2021 (APR 2021)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Security Subsystem (Apache Camel) — CVE-2020-11994
vendor_oracle·2021-01-15·CVSS 7.5
CVE-2020-11994 [HIGH] Oracle Oracle Fusion Middleware Risk Matrix: Security Subsystem (Apache Camel) — CVE-2020-11994
Oracle Oracle Fusion Middleware Risk Matrix: Security Subsystem (Apache Camel) vulnerability
CVE: CVE-2020-11994
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2021 (JAN 2021)
Red Hat
camel: server-side template injection and arbitrary file disclosure on templating components
vendor_redhat·2020-07-08·CVSS 7.5
CVE-2020-11994 [HIGH] CWE-88 camel: server-side template injection and arbitrary file disclosure on templating components
camel: server-side template injection and arbitrary file disclosure on templating components
Server-Side Template Injection and arbitrary file disclosure on Camel templating components
A flaw was found in camel. Camel's templating components are suseptable to Server-Side Template Injection and arbitrary file disclosure. The highest threat from this vulnerability is to data confidentiality.
Package: Camel (Red Hat BPM Suite 6) - Out of support scope
Package: Camel (Red Hat JBoss A-MQ 6) - Out of support scope
Package: Camel (Red Hat JBoss Fuse Service Works 6) - Out of support scope
Apache
Apache camel: CVE-2020-11994
vendor_apache·CVSS 7.5
CVE-2020-11994 [MEDIUM] Apache camel: CVE-2020-11994
Apache camel: CVE-2020-11994
2.22.x, 2.23.x, 2.24.x, 2.25.0 and 2.25.1, 3.0.0 up to 3.3.0 2.25.2, 3.4.0 MEDIUM Server-Side Template Injection and arbitrary file disclosure on Camel templating components
Severity: medium
No detection rules found.
No public exploits indexed.
https://lists.apache.org/thread.html/d0e00f2e147a9e9b13a6829133092f349b2882bf6860397368a52600%40%3Cannounce.tomcat.apache.org%3Ehttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://lists.apache.org/thread.html/d0e00f2e147a9e9b13a6829133092f349b2882bf6860397368a52600%40%3Cannounce.tomcat.apache.org%3Ehttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.html
2020-07-08
Published