Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-23114

Опубликовано: 19 фев. 2024
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

Deserialization of Untrusted Data vulnerability in Apache Camel CassandraQL Component AggregationRepository which is vulnerable to unsafe deserialization. Under specific conditions it is possible to deserialize malicious payload.This issue affects Apache Camel: from 3.0.0 before 3.21.4, from 3.22.0 before 3.22.1, from 4.0.0 before 4.0.4, from 4.1.0 before 4.4.0. Users are recommended to upgrade to version 4.4.0, which fixes the issue. If users are on the 4.0.x LTS releases stream, then they are suggested to upgrade to 4.0.4. If users are on 3.x, they are suggested to move to 3.21.4 or 3.22.1

A deserialization of untrusted data flaw was found in the Apache Camel CassandraQL Component AggregationRepository. The affected versions of Apache Camel are vulnerable to unsafe deserialization, where, under specific conditions, it is possible to deserialize a malicious payload.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Apache Camel 4 for Quarkus 3org.apache.camel-camel-cassandraqlNot affected
Red Hat build of Apache Camel for Spring Boot 3org.apache.camel-camel-cassandraqlNot affected
Red Hat build of Apache Camel for Spring Boot 4org.apache.camel-camel-cassandraqlNot affected
Red Hat Fuse 7org.apache.camel-camel-cassandraqlNot affected
Red Hat Integration Camel Quarkus 2org.apache.camel-camel-cassandraqlNot affected
RHINT Camel-K 1.10.8org.apache.camel-camel-cassandraqlFixedRHSA-2024:833922.10.2024

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-502
https://bugzilla.redhat.com/show_bug.cgi?id=2265053Camel-CassandraQL: Unsafe Deserialization from CassandraAggregationRepository

EPSS

Процентиль: 78%
0.01109
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
почти 2 года назад

Deserialization of Untrusted Data vulnerability in Apache Camel CassandraQL Component AggregationRepository which is vulnerable to unsafe deserialization. Under specific conditions it is possible to deserialize malicious payload.This issue affects Apache Camel: from 3.0.0 before 3.21.4, from 3.22.0 before 3.22.1, from 4.0.0 before 4.0.4, from 4.1.0 before 4.4.0. Users are recommended to upgrade to version 4.4.0, which fixes the issue. If users are on the 4.0.x LTS releases stream, then they are suggested to upgrade to 4.0.4. If users are on 3.x, they are suggested to move to 3.21.4 or 3.22.1

github
почти 2 года назад

Deserialization of Untrusted Data in Apache Camel CassandraQL

CVSS3: 9.8
fstec
почти 2 года назад

Уязвимость компонента CassandraQL java-фреймворка Apache Camel, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 78%
0.01109
Низкий

7.8 High

CVSS3