7.5
CVSSv2

CVE-2017-12634

Published: 15/11/2017 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The camel-castor component in Apache Camel 2.x prior to 2.19.4 and 2.20.x prior to 2.20.1 is vulnerable to Java object de-serialisation vulnerability. De-serializing untrusted data can lead to security flaws.

Vulnerable Product Search on Vulmon Subscribe to Product

apache camel

apache camel 2.20.0

Vendor Advisories

Synopsis Important: Red Hat JBoss Fuse/A-MQ 63 R6 security and bug fix update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat JBoss Fuse and Red Hat JBoss A-MQRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerabi ...
It was found that Apache Camel contains a security vulnerability via camel-castor component An attacker can utilize this flaw to deserialize a malicious object on the target machine which could lead to Remote Code Execution (RCE) ...