CVE-2013-4330: Code Injection
Apache Camel before 2.9.7, 2.10.0 before 2.10.7, 2.11.0 before 2.11.2, and 2.12.0 allows remote attackers to execute arbitrary simple language expressions by including "$simple{}" in a CamelFileName message header to a (1) FILE or (2) FTP producer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4330?
CVE-2013-4330 is considered a critical vulnerability that allows remote code execution.
How do I fix CVE-2013-4330?
To fix CVE-2013-4330, upgrade Apache Camel to version 2.9.7, 2.10.7, 2.11.2, or 2.12.1.
What versions of Apache Camel are affected by CVE-2013-4330?
CVE-2013-4330 affects Apache Camel versions before 2.9.7, 2.10.0 before 2.10.7, 2.11.0 before 2.11.2, and 2.12.0.
What can attackers do with CVE-2013-4330?
Attackers can exploit CVE-2013-4330 to execute arbitrary simple language expressions through specially crafted message headers.
Is there a workaround for CVE-2013-4330?
There are no official workarounds for CVE-2013-4330; upgrading to a secure version is recommended.