CVE-2020-11994: Apache Camel
High severity, CVSS 7.5. EPSS: 4.5% chance of exploitation in the next 30 days.
Server-Side Template Injection and arbitrary file disclosure on Camel templating components
Affected products
- Apache Camel: from 2.22.0, up to and including 2.22.5; from 2.23.0, up to and including 2.23.4; from 2.24.0, up to and including 2.24.3; from 3.0.0, up to and including 3.3.0; version 2.25.0 only; version 2.25.1 only
- Oracle Communications Diameter Signaling Router: from 8.0.0, up to and including 8.5.0
- Oracle Enterprise Manager Base Platform: version 13.4.0.0 only
- Oracle Enterprise Repository: version 11.1.1.7.0 only
Published 2020-07-08. Last modified 2026-06-17.