PT-2014-3427 · Apache · Apache Camel

Published

2014-03-20

·

Updated

2023-02-13

·

CVE-2014-0003

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Apache Camel versions 2.11.x through 2.11.3 Apache Camel versions 2.12.x through 2.12.2
Description The issue allows remote attackers to execute arbitrary Java methods via a crafted message, potentially leading to unauthorized access and control. This is related to the XSLT component in Apache Camel.
Recommendations For Apache Camel versions 2.11.x through 2.11.3, update to version 2.11.4 or later. For Apache Camel versions 2.12.x through 2.12.2, update to version 2.12.3 or later.

Exploit

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2014-0003
GHSA-H6RP-8V4J-HWPH
RHSA-2014:0245
RHSA-2014:0254

Affected Products

Apache Camel