9.8
CVSSv3

CVE-2020-11973

CVSSv4: NA | CVSSv3: 9.8 | CVSSv2: 7.5 | VMScore: 1000 | EPSS: 0.01914 | KEV: Not Included
Published: 14/05/2020 Updated: 21/11/2024

Vulnerability Summary

Apache Camel Netty enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache camel

oracle communications diameter signaling router

oracle enterprise manager base platform 13.3.0.0

oracle enterprise manager base platform 13.4.0.0

oracle flexcube private banking 12.0.0

oracle flexcube private banking 12.1.0

Vendor Advisories

Synopsis Important: Red Hat Fuse 780 release and security update Type/Severity Security Advisory: Important Topic A minor version update (from 77 to 78) is now available for Red Hat Fuse The purpose of this text-only errata is to inform you about the security issues fixed in this releaseRed Hat Produc ...

Mailing Lists

A new security advisory has been released for Apache Camel, that is fixed in the recent 2251 and 320 releases CVE-2020-11973: Apache Camel Netty enables Java deserialization by default Severity: MEDIUM Vendor: The Apache Software Foundation Versions Affected: Camel 2250, Camel 300 to 310 The unsupported Camel 2x (224 and earlier) ...