Reliance on Reverse DNS Resolution for a Security-Critical Action in Apache Camel - CVE-2020-11971

 

Reliance on Reverse DNS Resolution for a Security-Critical Action in Apache Camel - CVE-2020-11971

Published: May 17, 2020


Vulnerability identifier: #VU27956
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-11971
CWE-ID: CWE-350
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform spoofing attack.

The vulnerability exists due to Apache Camel JMX is vulnerable to DNS rebinding attack. A remote attacker can send specially crafted data to the application and perform spoofing attack.


Affected software

Apache Camel
Jazz for Service Management
IBM Tivoli Monitoring
IBM Tivoli Netcool Impact
Oracle Communications Diameter Intelligence Hub
SecureTransport
IBM Qradar SIEM
UrbanCode Build

How to mitigate CVE-2020-11971

Install updates from vendor's website.

Apache Camel - addressed in versions 2.25.1, 3.2.0
Jazz for Service Management - update to 1.1.3.25
SecureTransport - update to 5.5-20230629
IBM Tivoli Monitoring - update to 6.3.0.7 Service pack 13
IBM Tivoli Netcool Impact - update to 7.1.0.27
IBM Qradar SIEM - update to 7.5.0 Update Pack 6
UrbanCode Build - update to 6.1.7.10

External References

Related Security Bulletins