Apache Software Foundation Camel 2.16.4

CPE Details

Apache Software Foundation Camel 2.16.4
2.16.4
2017-05-01
18h29 +00:00
2017-05-01
18h29 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:apache:camel:2.16.4:*:*:*:*:*:*:*

Informations

Vendor

apache

Product

camel

Version

2.16.4

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2019-0188 2019-05-28 16h10 +00:00 Apache Camel prior to 2.24.0 contains an XML external entity injection (XXE) vulnerability (CWE-611) due to using an outdated vulnerable JSON-lib library. This affects only the camel-xmljson component, which was removed.
7.5
High
CVE-2019-0194 2019-04-30 19h30 +00:00 Apache Camel's File is vulnerable to directory traversal. Camel 2.21.0 to 2.21.3, 2.22.0 to 2.22.2, 2.23.0 and the unsupported Camel 2.x (2.19 and earlier) versions may be also affected.
7.5
High
CVE-2017-12633 2017-11-15 15h00 +00:00 The camel-hessian component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability. De-serializing untrusted data can lead to security flaws.
9.8
Critical
CVE-2017-12634 2017-11-15 15h00 +00:00 The camel-castor component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability. De-serializing untrusted data can lead to security flaws.
9.8
Critical
CVE-2016-8749 2017-03-28 16h00 +00:00 Apache Camel's Jackson and JacksonXML unmarshalling operation are vulnerable to Remote Code Execution attacks.
9.8
Critical