Apache Camel's File is vulnerable to directory traversal. Camel 2.21.0 to 2.21.3, 2.22.0 to 2.22.2, 2.23.0 and the unsupported Camel 2.x (2.19 and earlier) versions may be also affected.

Published at
2019-04-30
992 days ago
Modified
2019-05-24
968 days ago
2019
Year
The year of the turtle

http://www.securityfocus.com/bid/108181

BID:108181

https://lists.apache.org/thread.html/a39441db574ee996f829344491b3211b53c9ed926f00ae5d88943b76@%3Cdev.camel.apache.org%3E

MISC:https://lists.apache.org/thread.html/a39441db574ee996f829344491b3211b53c9ed926f00ae5d88943b76@%3Cdev.camel.apache.org%3E

https://lists.apache.org/thread.html/45e23ade8d3cb754615f95975e89e8dc73c59eeac914f07d53acbac6@%3Ccommits.camel.apache.org%3E

MLIST:[camel-commits] 20190430 [camel] branch master updated: Added CVE-2019-0194 details

https://lists.apache.org/thread.html/b4014ea7c5830ca1fc28edd5cafedfe93ad4af2d9e69c961c5def31d@%3Ccommits.camel.apache.org%3E

MLIST:[camel-commits] 20190430 svn commit: r1044347 - in /websites/production/camel/content: cache/main.pageCache security-advisories.data/CVE-2019-0194.txt.asc security-advisories.html

https://lists.apache.org/thread.html/9a6bc022f7ab28e4894b1831ce336eb41ae6d5c24d86646fe16e956f@%3Ccommits.camel.apache.org%3E

MLIST:[camel-commits] 20190524 [camel] 02/02: CVE-2019-0188 - Changed the title in security advisories

https://lists.apache.org/thread.html/0cb842f367336b352a7548e290116b64b78b8e7b99402deaba81a687@%3Ccommits.camel.apache.org%3E

MLIST:[camel-commits] 20190524 [camel] branch master updated: Added security advisory for CVE-2019-0188

https://lists.apache.org/thread.html/2318d7f7d87724d8716cd650c21b31cb06e4d34f6d0f5ee42f28fdaf@%3Ccommits.camel.apache.org%3E

MLIST:[camel-commits] 20190524 svn commit: r1045395 - in /websites/production/camel/content: cache/main.pageCache security-advisories.data/CVE-2019-0188.txt.asc security-advisories.html

https://lists.apache.org/thread.html/0a163d02169d3d361150e8183df4af33f1a3d8a419b2937ac8e6c66f@%3Cusers.camel.apache.org%3E

MLIST:[camel-users] 20190430 [SECURITY] New security advisory CVE-2019-0194 released for Apache Camel

http://www.openwall.com/lists/oss-security/2019/04/30/2

MLIST:[oss-security] 20190430 [SECURITY] New security advisory CVE-2019-0194 released for Apache Camel

Vulnerability RAW

{
	"Title": {
		"_text": "CVE-2019-0194"
	},
	"Notes": {
		"Note": [
			{
				"_text": "Apache Camel's File is vulnerable to directory traversal. Camel 2.21.0 to 2.21.3, 2.22.0 to 2.22.2, 2.23.0 and the unsupported Camel 2.x (2.19 and earlier) versions may be also affected."
			},
			{
				"_text": "2019-04-30"
			},
			{
				"_text": "2019-05-24"
			}
		]
	},
	"CVE": {
		"_text": "CVE-2019-0194"
	},
	"References": {
		"Reference": [
			{
				"URL": {
					"_text": "http://www.securityfocus.com/bid/108181"
				},
				"Description": {
					"_text": "BID:108181"
				}
			},
			{
				"URL": {
					"_text": "https://lists.apache.org/thread.html/a39441db574ee996f829344491b3211b53c9ed926f00ae5d88943b76@%3Cdev.camel.apache.org%3E"
				},
				"Description": {
					"_text": "MISC:https://lists.apache.org/thread.html/a39441db574ee996f829344491b3211b53c9ed926f00ae5d88943b76@%3Cdev.camel.apache.org%3E"
				}
			},
			{
				"URL": {
					"_text": "https://lists.apache.org/thread.html/45e23ade8d3cb754615f95975e89e8dc73c59eeac914f07d53acbac6@%3Ccommits.camel.apache.org%3E"
				},
				"Description": {
					"_text": "MLIST:[camel-commits] 20190430 [camel] branch master updated: Added CVE-2019-0194 details"
				}
			},
			{
				"URL": {
					"_text": "https://lists.apache.org/thread.html/b4014ea7c5830ca1fc28edd5cafedfe93ad4af2d9e69c961c5def31d@%3Ccommits.camel.apache.org%3E"
				},
				"Description": {
					"_text": "MLIST:[camel-commits] 20190430 svn commit: r1044347 - in /websites/production/camel/content: cache/main.pageCache security-advisories.data/CVE-2019-0194.txt.asc security-advisories.html"
				}
			},
			{
				"URL": {
					"_text": "https://lists.apache.org/thread.html/9a6bc022f7ab28e4894b1831ce336eb41ae6d5c24d86646fe16e956f@%3Ccommits.camel.apache.org%3E"
				},
				"Description": {
					"_text": "MLIST:[camel-commits] 20190524 [camel] 02/02: CVE-2019-0188 - Changed the title in security advisories"
				}
			},
			{
				"URL": {
					"_text": "https://lists.apache.org/thread.html/0cb842f367336b352a7548e290116b64b78b8e7b99402deaba81a687@%3Ccommits.camel.apache.org%3E"
				},
				"Description": {
					"_text": "MLIST:[camel-commits] 20190524 [camel] branch master updated: Added security advisory for CVE-2019-0188"
				}
			},
			{
				"URL": {
					"_text": "https://lists.apache.org/thread.html/2318d7f7d87724d8716cd650c21b31cb06e4d34f6d0f5ee42f28fdaf@%3Ccommits.camel.apache.org%3E"
				},
				"Description": {
					"_text": "MLIST:[camel-commits] 20190524 svn commit: r1045395 - in /websites/production/camel/content: cache/main.pageCache security-advisories.data/CVE-2019-0188.txt.asc security-advisories.html"
				}
			},
			{
				"URL": {
					"_text": "https://lists.apache.org/thread.html/0a163d02169d3d361150e8183df4af33f1a3d8a419b2937ac8e6c66f@%3Cusers.camel.apache.org%3E"
				},
				"Description": {
					"_text": "MLIST:[camel-users] 20190430 [SECURITY] New security advisory CVE-2019-0194 released for Apache Camel"
				}
			},
			{
				"URL": {
					"_text": "http://www.openwall.com/lists/oss-security/2019/04/30/2"
				},
				"Description": {
					"_text": "MLIST:[oss-security] 20190430 [SECURITY] New security advisory CVE-2019-0194 released for Apache Camel"
				}
			}
		]
	}
}