{"id":"GHSA-x9fv-c87w-55wc","summary":"Improper Control of Generation of Code in Apache Camel","details":"Apache Camel before 2.9.7, 2.10.0 before 2.10.7, 2.11.0 before 2.11.2, and 2.12.0 allows remote attackers to execute arbitrary simple language expressions by including \"$simple{}\" in a CamelFileName message header to a (1) FILE or (2) FTP producer.","aliases":["CVE-2013-4330"],"modified":"2024-12-06T05:39:49.459830Z","published":"2022-05-13T01:26:34Z","database_specific":{"cwe_ids":["CWE-94"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2022-07-08T19:19:37Z","nvd_published_at":"2013-10-04T17:55:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2013-4330"},{"type":"WEB","url":"https://github.com/apache/camel/commit/2281b1f365c50ee1a470fb9990b753eadee9095"},{"type":"WEB","url":"https://github.com/apache/camel/commit/27a9752a565fbef436bac4fcf22d339e3295b2a"},{"type":"WEB","url":"https://github.com/apache/camel/commit/3215fe50dd42c83a7a454dd36486843fe36eae4"},{"type":"WEB","url":"https://github.com/apache/camel/commit/5ba8f63f78f82b0cddf6cecbf59ac444a0cae2a6"},{"type":"WEB","url":"https://github.com/apache/camel/commit/ce19353f1297c5d3dc59be21a1ead89c0a44907"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/87542"},{"type":"WEB","url":"https://github.com/apache/camel"},{"type":"WEB","url":"https://issues.apache.org/jira/browse/CAMEL-6748"},{"type":"WEB","url":"https://lists.apache.org/thread.html/2318d7f7d87724d8716cd650c21b31cb06e4d34f6d0f5ee42f28fdaf%40%3Ccommits.camel.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/2318d7f7d87724d8716cd650c21b31cb06e4d34f6d0f5ee42f28fdaf@%3Ccommits.camel.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/b4014ea7c5830ca1fc28edd5cafedfe93ad4af2d9e69c961c5def31d%40%3Ccommits.camel.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/b4014ea7c5830ca1fc28edd5cafedfe93ad4af2d9e69c961c5def31d@%3Ccommits.camel.apache.org%3E"},{"type":"WEB","url":"http://camel.apache.org/security-advisories.data/CVE-2013-4330.txt.asc?version=1&modificationDate=1380535446943"},{"type":"WEB","url":"http://packetstormsecurity.com/files/123454"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2013-1862.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2014-0124.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2014-0140.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2014-0245.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2014-0254.html"},{"type":"WEB","url":"http://seclists.org/fulldisclosure/2013/Sep/178"}],"affected":[{"package":{"name":"org.apache.camel:camel-core","ecosystem":"Maven","purl":"pkg:maven/org.apache.camel/camel-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.9.7"}]}],"versions":["1.0.0","1.1.0","1.2.0","1.3.0","1.4.0","1.5.0","1.6.0","1.6.1","1.6.2","1.6.3","1.6.4","2.0-M1","2.0-M2","2.0-M3","2.0.0","2.1.0","2.2.0","2.3.0","2.4.0","2.5.0","2.6.0","2.7.0","2.7.1","2.7.2","2.7.3","2.7.4","2.7.5","2.8.0","2.8.1","2.8.2","2.8.3","2.8.4","2.8.5","2.8.6","2.9.0","2.9.0-RC1","2.9.1","2.9.2","2.9.3","2.9.4","2.9.5","2.9.6"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-x9fv-c87w-55wc/GHSA-x9fv-c87w-55wc.json"}},{"package":{"name":"org.apache.camel:camel-core","ecosystem":"Maven","purl":"pkg:maven/org.apache.camel/camel-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.10.0"},{"fixed":"2.10.7"}]}],"versions":["2.10.0","2.10.1","2.10.2","2.10.3","2.10.4","2.10.5","2.10.6"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-x9fv-c87w-55wc/GHSA-x9fv-c87w-55wc.json"}},{"package":{"name":"org.apache.camel:camel-core","ecosystem":"Maven","purl":"pkg:maven/org.apache.camel/camel-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.11.0"},{"fixed":"2.11.2"}]}],"versions":["2.11.0","2.11.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-x9fv-c87w-55wc/GHSA-x9fv-c87w-55wc.json"}},{"package":{"name":"org.apache.camel:camel-core","ecosystem":"Maven","purl":"pkg:maven/org.apache.camel/camel-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.12.0"},{"fixed":"2.12.1"}]}],"versions":["2.12.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-x9fv-c87w-55wc/GHSA-x9fv-c87w-55wc.json"}}],"schema_version":"1.9.0"}