CVE-2015-5348: High severity red hat build of apache camel vulnerability
Apache Camel 2.6.x through 2.14.x, 2.15.x before 2.15.5, and 2.16.x before 2.16.1, when using (1) camel-jetty or (2) camel-servlet as a consumer in Camel routes, allow remote attackers to execute arbitrary commands via a crafted serialized Java object in an HTTP request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5348?
CVE-2015-5348 is considered a critical vulnerability due to its ability to allow remote command execution using crafted serialized Java objects.
How do I fix CVE-2015-5348?
To resolve CVE-2015-5348, upgrade to Apache Camel version 2.15.5 or later, or version 2.16.1 or later.
What affected versions are impacted by CVE-2015-5348?
The affected versions of Apache Camel include all 2.6.x through 2.14.x, 2.15.x before 2.15.5, and 2.16.x before 2.16.1.
Which components of Apache Camel are vulnerable in CVE-2015-5348?
The camel-jetty and camel-servlet components are susceptible to the vulnerabilities outlined in CVE-2015-5348.
What are the potential consequences of exploiting CVE-2015-5348?
Exploitation of CVE-2015-5348 could lead to unauthorized remote command execution on the vulnerable application.