CVE-2017-12634
published 2017-11-15CVE-2017-12634: The camel-castor component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability…
PriorityP353critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
7.19%
93.6th percentile
The camel-castor component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability. De-serializing untrusted data can lead to security flaws.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | >= 2.0.0 < 2.19.4 | 2.19.4 |
| apache_software_foundation | apache_camel | — | — |
| apache_software_foundation | apache_camel | — | — |
| apache_software_foundation | apache_camel | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_apache9.8MEDIUM
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Camel-castor component in Apache Camel is vulnerable to Java object de-serialisation
ghsa·2018-10-16
CVE-2017-12634 [CRITICAL] CWE-502 Camel-castor component in Apache Camel is vulnerable to Java object de-serialisation
Camel-castor component in Apache Camel is vulnerable to Java object de-serialisation
The camel-castor component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability. De-serializing untrusted data can lead to security flaws.
OSV
Camel-castor component in Apache Camel is vulnerable to Java object de-serialisation
osv·2018-10-16
CVE-2017-12634 [CRITICAL] Camel-castor component in Apache Camel is vulnerable to Java object de-serialisation
Camel-castor component in Apache Camel is vulnerable to Java object de-serialisation
The camel-castor component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability. De-serializing untrusted data can lead to security flaws.
Red Hat
camel-castor: Apache Camel's Castor unmarshalling operation is vulnerable to Remote Code Execution attacks
vendor_redhat·2017-11-15·CVSS 9.8
CVE-2017-12634 [CRITICAL] CWE-502 camel-castor: Apache Camel's Castor unmarshalling operation is vulnerable to Remote Code Execution attacks
camel-castor: Apache Camel's Castor unmarshalling operation is vulnerable to Remote Code Execution attacks
The camel-castor component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability. De-serializing untrusted data can lead to security flaws.
It was found that Apache Camel contains a security vulnerability via camel-castor component. An attacker can utilize this flaw to deserialize a malicious object on the target machine which could lead to Remote Code Execution (RCE).
Package: camel-castor (Red Hat JBoss Fuse 6) - Affected
Package: camel-castor (Red Hat JBoss Fuse Service Works 6) - Out of support scope
Apache
Apache camel: CVE-2017-12634
vendor_apache·CVSS 9.8
CVE-2017-12634 [MEDIUM] Apache camel: CVE-2017-12634
Apache camel: CVE-2017-12634
2.19.0 up to 2.19.3, 2.20.0 2.19.4, 2.20.1 and newer MEDIUM Apache Camel's Castor unmarshalling operation is vulnerable to Remote Code Execution attacks
Severity: medium
No detection rules found.
No public exploits indexed.
http://camel.apache.org/security-advisories.data/CVE-2017-12634.txt.aschttp://www.securityfocus.com/bid/101876https://access.redhat.com/errata/RHSA-2018:0319https://issues.apache.org/jira/browse/CAMEL-11929https://lists.apache.org/thread.html/2318d7f7d87724d8716cd650c21b31cb06e4d34f6d0f5ee42f28fdaf%40%3Ccommits.camel.apache.org%3Ehttps://lists.apache.org/thread.html/b4014ea7c5830ca1fc28edd5cafedfe93ad4af2d9e69c961c5def31d%40%3Ccommits.camel.apache.org%3Ehttp://camel.apache.org/security-advisories.data/CVE-2017-12634.txt.aschttp://www.securityfocus.com/bid/101876https://access.redhat.com/errata/RHSA-2018:0319https://issues.apache.org/jira/browse/CAMEL-11929https://lists.apache.org/thread.html/2318d7f7d87724d8716cd650c21b31cb06e4d34f6d0f5ee42f28fdaf%40%3Ccommits.camel.apache.org%3Ehttps://lists.apache.org/thread.html/b4014ea7c5830ca1fc28edd5cafedfe93ad4af2d9e69c961c5def31d%40%3Ccommits.camel.apache.org%3E
2017-11-15
Published