Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xfxp-ppx7-cqrp

Опубликовано: 22 апр. 2026
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

camel-infinispan Vulnerable to Deserialization of Untrusted Data

A flaw was found in camel-infinispan. This vulnerability involves unsafe deserialization in the ProtoStream remote aggregation repository. A remote attacker with low privileges could exploit this by sending specially crafted data, leading to arbitrary code execution. This allows the attacker to gain full control over the affected system, impacting its confidentiality, integrity, and availability.

Пакеты

Наименование

org.apache.camel:camel-infinispan

maven
Затронутые версииВерсия исправления

< 4.20.0

4.20.0

EPSS

Процентиль: 48%
0.00667
Низкий

7.5 High

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 7.5
redhat
4 месяца назад

A flaw was found in camel-infinispan. This vulnerability involves unsafe deserialization in the ProtoStream remote aggregation repository. A remote attacker with low privileges could exploit this by sending specially crafted data, leading to arbitrary code execution. This allows the attacker to gain full control over the affected system, impacting its confidentiality, integrity, and availability.

CVSS3: 7.5
nvd
3 месяца назад

A flaw was found in camel-infinispan. This vulnerability involves unsafe deserialization in the ProtoStream remote aggregation repository. A remote attacker with low privileges could exploit this by sending specially crafted data, leading to arbitrary code execution. This allows the attacker to gain full control over the affected system, impacting its confidentiality, integrity, and availability.

EPSS

Процентиль: 48%
0.00667
Низкий

7.5 High

CVSS3

Дефекты

CWE-502