Vulnerability Description
Apache Camel's File is vulnerable to directory traversal. Camel 2.21.0 to 2.21.3, 2.22.0 to 2.22.2, 2.23.0 and the unsupported Camel 2.x (2.19 and earlier) versions may be also affected.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Camel | >= 2.0.0, <= 2.19.0 |
Related Weaknesses (CWE)
References
- http://www.openwall.com/lists/oss-security/2019/04/30/2ExploitMailing ListThird Party Advisory
- http://www.securityfocus.com/bid/108181
- https://lists.apache.org/thread.html/0a163d02169d3d361150e8183df4af33f1a3d8a419b
- https://lists.apache.org/thread.html/0cb842f367336b352a7548e290116b64b78b8e7b994
- https://lists.apache.org/thread.html/2318d7f7d87724d8716cd650c21b31cb06e4d34f6d0
- https://lists.apache.org/thread.html/45e23ade8d3cb754615f95975e89e8dc73c59eeac91
- https://lists.apache.org/thread.html/9a6bc022f7ab28e4894b1831ce336eb41ae6d5c24d8
- https://lists.apache.org/thread.html/a39441db574ee996f829344491b3211b53c9ed926f0
- https://lists.apache.org/thread.html/b4014ea7c5830ca1fc28edd5cafedfe93ad4af2d9e6
- http://www.openwall.com/lists/oss-security/2019/04/30/2ExploitMailing ListThird Party Advisory
- http://www.securityfocus.com/bid/108181
- https://lists.apache.org/thread.html/0a163d02169d3d361150e8183df4af33f1a3d8a419b
- https://lists.apache.org/thread.html/0cb842f367336b352a7548e290116b64b78b8e7b994
- https://lists.apache.org/thread.html/2318d7f7d87724d8716cd650c21b31cb06e4d34f6d0
- https://lists.apache.org/thread.html/45e23ade8d3cb754615f95975e89e8dc73c59eeac91
FAQ
What is CVE-2019-0194?
CVE-2019-0194 is a vulnerability with a CVSS score of 7.5 (HIGH). Apache Camel's File is vulnerable to directory traversal. Camel 2.21.0 to 2.21.3, 2.22.0 to 2.22.2, 2.23.0 and the unsupported Camel 2.x (2.19 and earlier) versions may be also affected.
How severe is CVE-2019-0194?
CVE-2019-0194 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-0194?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Camel.