Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vf4q-8mr7-5c5c

Опубликовано: 16 окт. 2018
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Camel-castor component in Apache Camel is vulnerable to Java object de-serialisation

The camel-castor component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability. De-serializing untrusted data can lead to security flaws.

Пакеты

Наименование

org.apache.camel:camel-castor

maven
Затронутые версииВерсия исправления

>= 2.0.0, < 2.19.4

2.19.4

Наименование

org.apache.camel:camel-castor

maven
Затронутые версииВерсия исправления

= 2.20.0

2.20.1

EPSS

Процентиль: 89%
0.04565
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 7.5
redhat
около 8 лет назад

The camel-castor component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability. De-serializing untrusted data can lead to security flaws.

CVSS3: 9.8
nvd
около 8 лет назад

The camel-castor component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability. De-serializing untrusted data can lead to security flaws.

EPSS

Процентиль: 89%
0.04565
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-502