CVE-2020-11994
Java vulnerability analysis and mitigation

Overview

Server-Side Template Injection (SSTI) vulnerability identified as CVE-2020-11994 affects Apache Camel's templating components including FreeMarker, Velocity, MVEL, and Mustache. The vulnerability was discovered and reported by the GitHub Security Lab team on April 29, 2020, and was officially disclosed on April 21, 2020. This vulnerability affects multiple templating components within Apache Camel, impacting both 2.x versions (up to 2.22.0) and 3.x versions (up to 3.2.0) (GitHub Security Lab).

Technical details

The vulnerability allows attackers to exploit template injection flaws in multiple Camel templating components. In FreeMarker, attackers can override template contents using the CamelFreemarkerTemplate header or provide a CamelFreemarkerResourceUri header to specify the URI of the template. Similar vulnerabilities exist in Velocity (CamelVelocityTemplate and CamelVelocityResourceUri headers) and MVEL (CamelMvelTemplate and CamelMvelResourceUri headers) components. Even with FreeMarker's ClassResolver sandbox enabled, attackers can bypass restrictions by abusing the camelContext object exposed to the template context (GitHub Security Lab).

Impact

The vulnerability can lead to Remote Code Execution (RCE) in FreeMarker, Velocity, and MVEL components, allowing attackers to execute arbitrary commands on the Camel system. Additionally, all affected components, including Mustache, are vulnerable to Arbitrary File Disclosure, enabling attackers to access sensitive file system resources (GitHub Security Lab).

Exploitability

The vulnerability can be exploited by sending malicious messages with specific headers to the affected components. For example, attackers can send messages to JMS queues with crafted template headers, though the attack vector may vary depending on the Camel consumer (e.g., JMS message properties, HTTP request headers). The vulnerability has been demonstrated to be exploitable through multiple templating engines (GitHub Security Lab).

Mitigation and workarounds

Oracle has included patches for this vulnerability in their Critical Patch Updates, as noted in their April 2021, January 2021, and October 2021 security advisories (Oracle CPU Apr2021, Oracle CPU Jan2021, Oracle CPU Oct2021).

Additional resources


SourceThis report was generated using AI

Related Java vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-63219HIGH8.6
  • Java logoJava
  • org.geonetwork-opensource:gn-services
NoYesSep 03, 2026
CVE-2026-49464HIGH8.1
  • Java logoJava
  • nl.nl-portal:taak
NoYesSep 11, 2026
CVE-2026-55864HIGH7.7
  • Java logoJava
  • org.geonetwork-opensource:gn-web-app
NoYesSep 09, 2026
CVE-2026-49463MEDIUM6.5
  • Java logoJava
  • nl.nl-portal:besluiten
NoYesSep 11, 2026
CVE-2026-49439MEDIUM4.3
  • Java logoJava
  • io.openremote:openremote-manager
NoYesSep 11, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management