CVE-2014-0003: High severity Apache Camel vulnerability
It was found that the Apache Camel XSLT component allowed XSL stylesheets to perform calls to external Java methods. A remote attacker able to submit messages to an xslt: Camel route could use this flaw to perform arbitrary remote code execution in the context of the Camel server process.
Other sources
The XSLT component in Apache Camel 2.11.x before 2.11.4, 2.12.x before 2.12.3, and possibly earlier versions allows remote attackers to execute arbitrary Java methods via a crafted message.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.apache.camel:camel-coreto a version that resolves this vulnerability.Fixed in 2.12.3 - Upgrade
Upgrade
maven/org.apache.camel:camel-coreto a version that resolves this vulnerability.Fixed in 2.11.4 - Upgrade
Upgrade
Apache Camel XSLT componentto a version that resolves this vulnerability.Fixed in 2.11.4 - Upgrade
Upgrade
Apache Camel XSLT componentto a version that resolves this vulnerability.Fixed in 2.12.3
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0003?
The severity of CVE-2014-0003 is considered critical due to the potential for arbitrary remote code execution.
How do I fix CVE-2014-0003?
To fix CVE-2014-0003, upgrade Apache Camel to version 2.11.4 or higher, or to version 2.12.3 or higher.
Which versions of Apache Camel are affected by CVE-2014-0003?
CVE-2014-0003 affects Apache Camel versions 1.0.0 up to and including 2.11.3.
What type of vulnerability is CVE-2014-0003?
CVE-2014-0003 is a remote code execution vulnerability that allows attackers to execute arbitrary code on the server.
Can CVE-2014-0003 be exploited remotely?
Yes, CVE-2014-0003 can be exploited remotely by an attacker who can submit messages to an XSLT Camel route.