CVE-2015-5348
high
CVSS v3
8.1
CVSS v2
6.8
VIR risk
8.1
Description
Apache Camel can allow remote attackers to execute arbitrary commands
Predictions
Exploit likelihood
88%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: secalert@redhat.com — https://issues.apache.org/jira/browse/CAMEL-9309
Vendor advisory: secalert@redhat.com — http://camel.apache.org/security-advisories.data/CVE-2015-5348.txt.asc
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Maven | org.apache.camel:camel-jetty | <2.15.5 | 2.15.5 |
| Maven | org.apache.camel:camel-jetty | >=2.16.0,<2.16.1 | 2.16.1 |
| Maven | org.apache.camel:camel-servlet | <2.15.5 | 2.15.5 |
| Maven | org.apache.camel:camel-servlet | >=2.16.0,<2.16.1 | 2.16.1 |
| Maven | org.apache.camel:camel-http | <2.15.5 | 2.15.5 |
| Maven | org.apache.camel:camel-http | >=2.16.0,<2.16.1 | 2.16.1 |
| Maven | org.apache.camel:camel-http-common | <2.15.5 | 2.15.5 |
| Maven | org.apache.camel:camel-http-common | >=2.16.0,<2.16.1 | 2.16.1 |
| Maven | org.apache.camel:camel-http4 | <2.15.5 | 2.15.5 |
| Maven | org.apache.camel:camel-http4 | >=2.16.0,<2.16.1 | 2.16.1 |
| Maven | org.apache.camel:camel-ahc | <2.15.5 | 2.15.5 |
| Maven | org.apache.camel:camel-ahc | >=2.16.0,<2.16.1 | 2.16.1 |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| apache | camel | 2.6.0 | |
| apache | camel | 2.7.0 | |
| apache | camel | 2.7.1 | |
| apache | camel | 2.7.2 | |
| apache | camel | 2.7.3 | |
| apache | camel | 2.7.4 | |
| apache | camel | 2.7.5 | |
| apache | camel | 2.8.0 | |
| apache | camel | 2.8.1 | |
| apache | camel | 2.8.2 | |
| apache | camel | 2.8.3 | |
| apache | camel | 2.8.4 | |
| apache | camel | 2.8.5 | |
| apache | camel | 2.8.6 | |
| apache | camel | 2.9.0 | |
| apache | camel | 2.9.1 | |
| apache | camel | 2.9.2 | |
| apache | camel | 2.9.3 | |
| apache | camel | 2.9.4 | |
| apache | camel | 2.9.5 | |
| apache | camel | 2.9.6 | |
| apache | camel | 2.9.7 | |
| apache | camel | 2.9.8 | |
| apache | camel | 2.10.0 | |
| apache | camel | 2.10.1 | |
| apache | camel | 2.10.2 | |
| apache | camel | 2.10.3 | |
| apache | camel | 2.10.4 | |
| apache | camel | 2.10.5 | |
| apache | camel | 2.10.6 | |
| apache | camel | 2.10.7 | |
| apache | camel | 2.11.0 | |
| apache | camel | 2.11.1 | |
| apache | camel | 2.11.2 | |
| apache | camel | 2.11.3 | |
| apache | camel | 2.11.4 | |
| apache | camel | 2.12.0 | |
| apache | camel | 2.12.1 | |
| apache | camel | 2.12.2 | |
| apache | camel | 2.12.3 | |
| apache | camel | 2.12.4 | |
| apache | camel | 2.12.5 | |
| apache | camel | 2.13.0 | |
| apache | camel | 2.13.1 | |
| apache | camel | 2.13.2 | |
| apache | camel | 2.13.3 | |
| apache | camel | 2.13.4 | |
| apache | camel | 2.14.0 | |
| apache | camel | 2.14.1 | |
| apache | camel | 2.14.2 | |
| apache | camel | 2.14.3 | |
| apache | camel | 2.14.4 | |
| apache | camel | 2.15.0 | |
| apache | camel | 2.15.1 | |
| apache | camel | 2.15.2 | |
| apache | camel | 2.15.3 | |
| apache | camel | 2.15.4 | |
| apache | camel | 2.16.0 | |
References
- http://camel.apache.org/security-advisories.data/CVE-2015-5348.txt.asc
- http://packetstormsecurity.com/files/134946/Apache-Camel-Java-Object-Deserialization.html
- http://rhn.redhat.com/errata/RHSA-2016-2035.html
- http://www.securityfocus.com/archive/1/537147/100/0/threaded
- http://www.securityfocus.com/bid/80696
- https://issues.apache.org/jira/browse/CAMEL-9309
- https://lists.apache.org/thread.html/2318d7f7d87724d8716cd650c21b31cb06e4d34f6d0f5ee42f28fdaf%40%3Ccommits.camel.apache.org%3E
- https://lists.apache.org/thread.html/b4014ea7c5830ca1fc28edd5cafedfe93ad4af2d9e69c961c5def31d%40%3Ccommits.camel.apache.org%3E
- https://nvd.nist.gov/vuln/detail/CVE-2015-5348
- https://github.com/apache/camel/commit/f7f0b18f6924fe0b01f32a25ed1e38e29b1bf8e5
- https://github.com/apache/camel/commit/e7fd5f049c2fd51a528f8062da91a1c75e33b0e8
- https://github.com/apache/camel/commit/d853853469292cd54fd9662c3605030ab5a9566b
- https://github.com/apache/camel/commit/c558f30a6d3820faa3d8c4ad5e54448914ec60d0
- https://github.com/apache/camel/commit/c47cffcadabca0c588753555a386942184a33627
- https://github.com/apache/camel/commit/a68434c258cdcd30587ae7adc5dabbac43eadbbf
- https://github.com/apache/camel/commit/9cbd5867fe73ef07ecba6f16d64689632e3f2a16
- https://github.com/apache/camel/commit/94330f99acb6f28155793b253de9956c3798f3bb
- https://github.com/apache/camel/commit/92081b203523c5ed502ed41df43cbd8655caf9b9
- https://github.com/apache/camel/commit/7e28d0af471ea992eb74807a4abd1626b88d678a
- https://github.com/apache/camel/commit/735ee02c693964b5f700af13a2adfeae56b848a4
- https://github.com/apache/camel/commit/5ea0a6f6c6a54f1cddf9691a99b0c237afc95348
- https://github.com/apache/camel/commit/515c822148d52de9e7cdf4f6b01f7b793f2f273f
- https://github.com/apache/camel/commit/4f065fe07c1dcd7b451e6005a6dc8e96d77da43e
- https://github.com/apache/camel/commit/44e6a3036e5a11d90b60c142cf51ed74b792de31
- https://github.com/apache/camel/commit/349109b0834764560f0be69eb74f43a16bd220b0
CWEs
CWE-19
Verify integrity in audit chain (admin only). AS-IS.