First published: Fri Jul 10 2020(Updated: )
Server-Side Template Injection and arbitrary file disclosure on Camel templating components. Reference: <a href="https://camel.apache.org/security/CVE-2020-11994.html">https://camel.apache.org/security/CVE-2020-11994.html</a>
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Build of Apache Camel |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1855786 is classified as critical due to the potential for server-side template injection and arbitrary file disclosure.
To fix REDHAT-BUG-1855786, update to the latest version of Apache Camel that includes patches for this vulnerability.
REDHAT-BUG-1855786 allows for server-side template injection attacks and may enable arbitrary file disclosures on affected systems.
Systems using affected versions of Apache Camel are vulnerable to REDHAT-BUG-1855786.
The potential impacts of REDHAT-BUG-1855786 include unauthorized access to sensitive files and the ability to manipulate server-side processes.