CVE-2018-8041: Path Traversal
Apache Camel's Mail 2.20.0 through 2.20.3, 2.21.0 through 2.21.1 and 2.22.0 is vulnerable to path traversal.
Other sources
It was found that apache camel-mail is vulnerable to path traversal vulnerability when in the position of receiving MUA. While camel-mail does not write the attachment to an arbitrary paths, it does not prevent user code from utilizing this functionality to be exposed to such vulnerability.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2018-8041.
What is the severity of CVE-2018-8041?
The severity of CVE-2018-8041 is medium (6.3).
Which software versions are affected by CVE-2018-8041?
Apache Camel's Mail versions 2.20.0 through 2.20.3, 2.21.0 through 2.21.1, and 2.22.0 are affected by CVE-2018-8041.
What is the CWE ID of CVE-2018-8041?
The CWE ID of CVE-2018-8041 is 22.
How can I fix the path traversal vulnerability in Apache Camel's Mail?
It is recommended to update to a version that is not vulnerable: use Apache Camel's Mail version 2.20.4 or higher, 2.21.2 or higher, or 2.22.1 or higher.