VDB
CVE-2013-4330
CVE-2013-4330
PUBLISHED
Reported by redhat · Published October 4, 2013
Apache Camel before 2.9.7, 2.10.0 before 2.10.7, 2.11.0 before 2.11.2, and 2.12.0 allows remote attackers to execute arbitrary simple language expressions by including "$simple{}" in a CamelFileName message header to a (1) FILE or (2) FTP producer.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| n/a | n/a | n/a, n/a, n/a |
| Maven | org.apache.camel:camel-core | 0, 0 |
Timeline
- Oct 4, 2013 CVE Published
- May 24, 2019 CVE Updated
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 3, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Feb 8, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Sep 7, 2023 EPSS Score
References
- 54888 third-party-advisoryx_refsource_SECUNIA
- 20130930 CVE-2013-4330: Apache Camel critical disclosure vulnerability mailing-listx_refsource_FULLDISC
- RHSA-2013:1862 vendor-advisoryx_refsource_REDHAT
- apache-camel-cve20134330-code-exec(87542) vdb-entryx_refsource_XF
- RHSA-2014:0140 vendor-advisoryx_refsource_REDHAT
- RHSA-2014:0124 vendor-advisoryx_refsource_REDHAT
- RHSA-2014:0254 vendor-advisoryx_refsource_REDHAT
- 97941 vdb-entryx_refsource_OSVDB
- RHSA-2014:0245 vendor-advisoryx_refsource_REDHAT
- x_refsource_CONFIRM
- x_refsource_MISC
- [camel-commits] 20190430 svn commit: r1044347 - in /websites/production/camel/content: cache/main.pageCache security-advisories.data/CVE-2019-0194.txt.asc security-advisories.html mailing-listx_refsource_MLIST
- [camel-commits] 20190524 svn commit: r1045395 - in /websites/production/camel/content: cache/main.pageCache security-advisories.data/CVE-2019-0188.txt.asc security-advisories.html mailing-listx_refsource_MLIST
- http://camel.apache.org/security-advisories.data/CVE-2013-4330.txt.asc url
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-4330 url
- https://issues.apache.org/jira/browse/CAMEL-6734 url
- https://issues.apache.org/jira/browse/CAMEL-6748 url