9.8
CVSSv3

CVE-2020-11973

Published: 14/05/2020 Updated: 05/10/2022
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Apache Camel Netty enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache camel

oracle flexcube private banking 12.1.0

oracle flexcube private banking 12.0.0

oracle enterprise manager base platform 13.3.0.0

oracle enterprise manager base platform 13.4.0.0

oracle communications diameter signaling router

Vendor Advisories

Synopsis Important: Red Hat Fuse 780 release and security update Type/Severity Security Advisory: Important Topic A minor version update (from 77 to 78) is now available for Red Hat Fuse The purpose of this text-only errata is to inform you about the security issues fixed in this releaseRed Hat Produc ...

Mailing Lists

A new security advisory has been released for Apache Camel, that is fixed in the recent 2251 and 320 releases CVE-2020-11973: Apache Camel Netty enables Java deserialization by default Severity: MEDIUM Vendor: The Apache Software Foundation Versions Affected: Camel 2250, Camel 300 to 310 The unsupported Camel 2x (224 and earlier) ...