imPC@ndo IT

Tracker / CVE-2020-11994

CVE-2020-11994

High 7.5

Server-Side Template Injection and arbitrary file disclosure on Camel templating components

Affected products and versions

apache camel
apache camel · 2.22.0 → 2.22.5
apache camel · 2.23.0 → 2.23.4
apache camel · 2.24.0 → 2.24.3
apache camel · 3.0.0 → 3.3.0
oracle communications_diameter_signaling_router · 8.0.0 → 8.5.0
oracle enterprise_manager_base_platform
oracle enterprise_repository

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References