Apache Camel CVE-2019-0194 Directory Traversal Vulnerability
BID:108181
CVE-2019-194 |Info
Apache Camel CVE-2019-0194 Directory Traversal Vulnerability
| Bugtraq ID: | 108181 |
| Class: | Input Validation Error |
| CVE: |
CVE-2019-0194 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 30 2019 12:00AM |
| Updated: | Apr 30 2019 12:00AM |
| Credit: | Colm O. HEigeartaigh |
| Vulnerable: |
Apache Camel 2.23 Apache Camel 2.22.2 Apache Camel 2.22.1 Apache Camel 2.22 Apache Camel 2.21.3 Apache Camel 2.21.2 Apache Camel 2.21.1 Apache Camel 2.21 |
| Not Vulnerable: |
Apache Camel 3.0 Apache Camel 2.24 Apache Camel 2.23.1 Apache Camel 2.22.3 Apache Camel 2.21.5 |
Discussion
Apache Camel CVE-2019-0194 Directory Traversal Vulnerability
Apache Camel is prone to a directory-traversal vulnerability.
A remote attacker could exploit the vulnerability using directory-traversal characters ('../') to access arbitrary files that contain sensitive information.
Camel 2.21.0 through 2.21.3, Camel 2.22.0 through 2.22.2 and Camel 2.23.0 are vulnerable; other unsupported versions may also be vulnerable.
Apache Camel is prone to a directory-traversal vulnerability.
A remote attacker could exploit the vulnerability using directory-traversal characters ('../') to access arbitrary files that contain sensitive information.
Camel 2.21.0 through 2.21.3, Camel 2.22.0 through 2.22.2 and Camel 2.23.0 are vulnerable; other unsupported versions may also be vulnerable.
Exploit / POC
Apache Camel CVE-2019-0194 Directory Traversal Vulnerability
An attacker can exploit this issue using a web browser.
An attacker can exploit this issue using a web browser.
Solution / Fix
Apache Camel CVE-2019-0194 Directory Traversal Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Apache Camel CVE-2019-0194 Directory Traversal Vulnerability
References:
References: