Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vvjc-q5vr-52q6

Опубликовано: 16 окт. 2018
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Apache Camel's Jackson and JacksonXML unmarshalling operation are vulnerable to Remote Code Execution attacks

Apache Camel's camel-jackson and camel-jacksonxml components are vulnerable to Java object de-serialisation vulnerability. Camel allows to specify such a type through the 'CamelJacksonUnmarshalType' property. De-serializing untrusted data can lead to security flaws as demonstrated in various similar reports about Java de-serialization issues.

Mitigation: 2.16.x users should upgrade to 2.16.5, 2.17.x users should upgrade to 2.17.5, 2.18.x users should upgrade to 2.18.2.

The JIRA tickets: https://issues.apache.org/jira/browse/CAMEL-10567 and https://issues.apache.org/jira/browse/CAMEL-10604 refers to the various commits that resovoled the issue, and have more details.

Ссылки

Пакеты

Наименование

org.apache.camel:camel-jackson

maven
Затронутые версииВерсия исправления

< 2.16.5

2.16.5

Наименование

org.apache.camel:camel-jackson

maven
Затронутые версииВерсия исправления

>= 2.17.0, < 2.17.5

2.17.5

Наименование

org.apache.camel:camel-jackson

maven
Затронутые версииВерсия исправления

>= 2.18.0, < 2.18.2

2.18.2

EPSS

Процентиль: 90%
0.05584
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 8.1
redhat
около 9 лет назад

Apache Camel's Jackson and JacksonXML unmarshalling operation are vulnerable to Remote Code Execution attacks.

CVSS3: 9.8
nvd
почти 9 лет назад

Apache Camel's Jackson and JacksonXML unmarshalling operation are vulnerable to Remote Code Execution attacks.

EPSS

Процентиль: 90%
0.05584
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-502