{"id":"CVE-2019-0194","details":"Apache Camel's File is vulnerable to directory traversal. Camel 2.21.0 to 2.21.3, 2.22.0 to 2.22.2, 2.23.0 and the unsupported Camel 2.x (2.19 and earlier) versions may be also affected.","aliases":["GHSA-4wjq-69rc-8wcp"],"modified":"2026-07-08T20:05:06.413509Z","published":"2019-04-30T22:29:00.607Z","references":[{"type":"WEB","url":"http://www.securityfocus.com/bid/108181"},{"type":"WEB","url":"https://lists.apache.org/thread.html/0a163d02169d3d361150e8183df4af33f1a3d8a419b2937ac8e6c66f%40%3Cusers.camel.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/0cb842f367336b352a7548e290116b64b78b8e7b99402deaba81a687%40%3Ccommits.camel.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/2318d7f7d87724d8716cd650c21b31cb06e4d34f6d0f5ee42f28fdaf%40%3Ccommits.camel.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/45e23ade8d3cb754615f95975e89e8dc73c59eeac914f07d53acbac6%40%3Ccommits.camel.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/9a6bc022f7ab28e4894b1831ce336eb41ae6d5c24d86646fe16e956f%40%3Ccommits.camel.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/a39441db574ee996f829344491b3211b53c9ed926f00ae5d88943b76%40%3Cdev.camel.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/b4014ea7c5830ca1fc28edd5cafedfe93ad4af2d9e69c961c5def31d%40%3Ccommits.camel.apache.org%3E"},{"type":"EVIDENCE","url":"http://www.openwall.com/lists/oss-security/2019/04/30/2"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/camel","events":[{"introduced":"6c88ad61b73dbfbc49c62624096ca0c250111430"},{"last_affected":"6cb00233e8e94dc9028f9ec02b5580d04de24c66"},{"introduced":"36bea62e844c5037b8c4d9e0eab5cc6b189fe1da"},{"last_affected":"d9d91408da0c99ed5538e23ba1d404d0342900db"},{"introduced":"363777cc93ab6072cd12d2a231c2165cbc6c0524"},{"last_affected":"65d603ddf448e8450dbe4c86abd2bed475c451c5"},{"introduced":"675a6149321065b076b5d9a4ba9dfc29a2e72a3d"},{"last_affected":"675a6149321065b076b5d9a4ba9dfc29a2e72a3d"}],"database_specific":{"cpe":["cpe:2.3:a:apache:camel:*:*:*:*:*:*:*:*","cpe:2.3:a:apache:camel:2.23.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"2.0.0"},{"last_affected":"2.19.0"},{"introduced":"2.21.0"},{"last_affected":"2.21.3"},{"introduced":"2.22.0"},{"last_affected":"2.22.2"},{"introduced":"2.23.0"},{"last_affected":"2.23.0"}],"source":["CPE_RANGE","CPE_STRING"]}}],"versions":["2.23.0","camel-2.23.0","camel-2.22.2","camel-2.22.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-0194.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}