Camel-castor component in Apache Camel is vulnerable to Java object de-serialisation
Critical severity
GitHub Reviewed
Published
Oct 16, 2018
to the GitHub Advisory Database
•
Updated Dec 13, 2023
Package
Affected versions
>= 2.0.0, < 2.19.4
= 2.20.0
Patched versions
2.19.4
2.20.1
Description
Published to the GitHub Advisory Database
Oct 16, 2018
Reviewed
Jun 16, 2020
Last updated
Dec 13, 2023
The camel-castor component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability. De-serializing untrusted data can lead to security flaws.
References