Rule, routing, workflow, and pipeline products let operators express logic as data: a Camel route condition, a Drools rule consequence, a Camunda process expression, a Logstash filter. Each ships its own expression or scripting layer, and each evaluates that layer against the messages or events flowing through it. When any part of that expression is built from untrusted input, the attacker controls the logic the engine runs, and on these engines that logic reaches a full language with host access.
Every engine in this group reaches code execution, though through a different language:
- Apache Camel: the Simple language (
${...}) invokes beans and methods, and routes using the OGNL or SpEL components reach method calls and the runtime. - Camunda: BPMN uses Unified EL (JUEL)
${...}bound to Java methods, and script tasks run Groovy or JavaScript directly. - Drools: rule conditions and consequences use the MVEL dialect, which has full Java access.
- ELK Logstash: the pipeline
rubyfilter executes arbitrary Ruby supplied in itscodeoption.
The JVM engines here share the Runtime.exec(String) shell caveat: the single-string form tokenizes on whitespace with no shell, so shell features require an explicit String[]{"/bin/bash","-c","..."} vector through ProcessBuilder. The Logstash page covers the Ruby equivalent.