Apache Software Foundation Camel 2.18.5

CPE Details

Apache Software Foundation Camel 2.18.5
2.18.5
2019-05-01
16h35 +00:00
2019-05-01
16h35 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:apache:camel:2.18.5:*:*:*:*:*:*:*

Informations

Vendor

apache

Product

camel

Version

2.18.5

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2019-0188 2019-05-28 16h10 +00:00 Apache Camel prior to 2.24.0 contains an XML external entity injection (XXE) vulnerability (CWE-611) due to using an outdated vulnerable JSON-lib library. This affects only the camel-xmljson component, which was removed.
7.5
Haute
CVE-2019-0194 2019-04-30 19h30 +00:00 Apache Camel's File is vulnerable to directory traversal. Camel 2.21.0 to 2.21.3, 2.22.0 to 2.22.2, 2.23.0 and the unsupported Camel 2.x (2.19 and earlier) versions may be also affected.
7.5
Haute
CVE-2017-12633 2017-11-15 15h00 +00:00 The camel-hessian component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability. De-serializing untrusted data can lead to security flaws.
9.8
Critique
CVE-2017-12634 2017-11-15 15h00 +00:00 The camel-castor component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability. De-serializing untrusted data can lead to security flaws.
9.8
Critique