VDB
CVE-2024-51132
CVE-2024-51132
PUBLISHED
Es bestehen mehrere Schwachstellen in Apache Camel für Spring Boot. Diese Fehler existieren wegen der unsachgemäßen Behandlung von XML-Entitäten und Transformationen in der Komponente Fast Healthcare Interoperability Resources (HAPI FHIR). Ein entfernter, anonymer Angreifer kann diese Schwachstellen ausnutzen, um beliebigen Code auszuführen oder auf vertrauliche Informationen zuzugreifen.
EPSS 7.94% · 92.2th percentile
Risk Scores
EPSS Score
7.94%
92.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat Enterprise Linux | |
| Apache | Apache Camel <4.4.4 |
Exploit Intelligence
- JAckLosingHeart/CVE-2024-51132-POC (github-poc)
- JAckLosingHeart/CVE-2024-51132-POC (github-poc)
- JAckLosingHeart/CVE-2024-51132-POC (github-poc)
- JAckLosingHeart/CVE-2024-51132-POC (github-poc)
- JAckLosingHeart/CVE-2024-51132-POC (github-poc)
- JAckLosingHeart/CVE-2024-51132-POC (github-poc)
- JAckLosingHeart/CVE-2024-51132-POC (github-poc)
- JAckLosingHeart/CVE-2024-51132-POC (github-poc)
- CIRCL seen: CVE-2024-51132 (circl-sighting)
- https://github.com/hapifhir/org.hl7.fhir.core (circl)
…and 1 more exploits
Timeline
- Nov 5, 2024 CVE Published
- Nov 5, 2024 PoC Published
- Nov 6, 2024 EPSS Score
- Nov 6, 2024 Coalition ESS Score
- Nov 12, 2024 Coalition ESS Score
- Nov 19, 2024 CVE Updated
- Dec 13, 2024 EPSS Score
- Dec 31, 2024 EPSS Score
- Feb 4, 2025 EPSS Score
- Mar 12, 2025 EPSS Score
- Mar 17, 2025 EPSS Score
- Mar 20, 2025 Coalition ESS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-3485.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-3485 advisory
- https://access.redhat.com/errata/RHSA-2024:9806 advisory
- https://github.com/JAckLosingHeart/CVE-2024-51132-POC exploit
- https://access.redhat.com/errata/RHSA-2024:10035 advisory