
Cloud Vulnerability DB
A community-led vulnerabilities database
Server-Side Template Injection (SSTI) vulnerability identified as CVE-2020-11994 affects Apache Camel's templating components including FreeMarker, Velocity, MVEL, and Mustache. The vulnerability was discovered and reported by the GitHub Security Lab team on April 29, 2020, and was officially disclosed on April 21, 2020. This vulnerability affects multiple templating components within Apache Camel, impacting both 2.x versions (up to 2.22.0) and 3.x versions (up to 3.2.0) (GitHub Security Lab).
The vulnerability allows attackers to exploit template injection flaws in multiple Camel templating components. In FreeMarker, attackers can override template contents using the CamelFreemarkerTemplate header or provide a CamelFreemarkerResourceUri header to specify the URI of the template. Similar vulnerabilities exist in Velocity (CamelVelocityTemplate and CamelVelocityResourceUri headers) and MVEL (CamelMvelTemplate and CamelMvelResourceUri headers) components. Even with FreeMarker's ClassResolver sandbox enabled, attackers can bypass restrictions by abusing the camelContext object exposed to the template context (GitHub Security Lab).
The vulnerability can lead to Remote Code Execution (RCE) in FreeMarker, Velocity, and MVEL components, allowing attackers to execute arbitrary commands on the Camel system. Additionally, all affected components, including Mustache, are vulnerable to Arbitrary File Disclosure, enabling attackers to access sensitive file system resources (GitHub Security Lab).
The vulnerability can be exploited by sending malicious messages with specific headers to the affected components. For example, attackers can send messages to JMS queues with crafted template headers, though the attack vector may vary depending on the Camel consumer (e.g., JMS message properties, HTTP request headers). The vulnerability has been demonstrated to be exploitable through multiple templating engines (GitHub Security Lab).
Oracle has included patches for this vulnerability in their Critical Patch Updates, as noted in their April 2021, January 2021, and October 2021 security advisories (Oracle CPU Apr2021, Oracle CPU Jan2021, Oracle CPU Oct2021).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."