CVE-2020-11973
published 2020-05-14CVE-2020-11973: Apache Camel Netty enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should…
PriorityP354critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
6.59%
93.1th percentile
Apache Camel Netty enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | camel | — | — |
| apache | camel | 2.22.0 – 2.25.0 | — |
| apache | camel | 3.0.0 – 3.1.0 | — |
| oracle | communications_diameter_signaling_router | 8.0.0 – 8.5.0 | — |
| oracle | enterprise_manager_base_platform | — | — |
| oracle | enterprise_manager_base_platform | — | — |
| oracle | flexcube_private_banking | — | — |
| oracle | flexcube_private_banking | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_apache9.8MEDIUM
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Apache Camel Netty enables Java deserialization by default
osv·2020-05-21
CVE-2020-11973 [CRITICAL] Apache Camel Netty enables Java deserialization by default
Apache Camel Netty enables Java deserialization by default
Apache Camel Netty enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0.
GHSA
Apache Camel Netty enables Java deserialization by default
ghsa·2020-05-21
CVE-2020-11973 [CRITICAL] CWE-502 Apache Camel Netty enables Java deserialization by default
Apache Camel Netty enables Java deserialization by default
Apache Camel Netty enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0.
Oracle
Oracle Oracle Enterprise Manager Risk Matrix: Reporting Framework (Apache Camel) — CVE-2020-11973
vendor_oracle·2021-01-15·CVSS 9.8
CVE-2020-11973 [CRITICAL] Oracle Oracle Enterprise Manager Risk Matrix: Reporting Framework (Apache Camel) — CVE-2020-11973
Oracle Oracle Enterprise Manager Risk Matrix: Reporting Framework (Apache Camel) vulnerability
CVE: CVE-2020-11973
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2021 (JAN 2021)
Oracle
Oracle Oracle Communications Risk Matrix: IDIH (Apache Camel) — CVE-2020-11973
vendor_oracle·2020-10-15·CVSS 9.8
CVE-2020-11973 [CRITICAL] Oracle Oracle Communications Risk Matrix: IDIH (Apache Camel) — CVE-2020-11973
Oracle Oracle Communications Risk Matrix: IDIH (Apache Camel) vulnerability
CVE: CVE-2020-11973
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2020 (OCT 2020)
Red Hat
camel: Netty enables Java deserialization by default which could leed to remote code execution
vendor_redhat·2020-05-14·CVSS 9.8
CVE-2020-11973 [CRITICAL] CWE-502 camel: Netty enables Java deserialization by default which could leed to remote code execution
camel: Netty enables Java deserialization by default which could leed to remote code execution
Apache Camel Netty enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0.
A flaw was found in camel. Apache Camel RabbitMQ enables java deserialization, by default, without any means of disabling which can lead to arbitrary code being executed. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Statement: Red Hat JBoss Fuse 6 and Red Hat Fuse 7 distribute camel with the affected `camel-netty` component. However both Fuse 6 and Fuse 7 have deprecated the `camel-netty` component which uses netty 3.x
Apache
Apache camel: CVE-2020-11973
vendor_apache·CVSS 9.8
CVE-2020-11973 [MEDIUM] Apache camel: CVE-2020-11973
Apache camel: CVE-2020-11973
2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 2.25.1, 3.2.0 MEDIUM Apache Camel Netty enables Java deserialization by default
Severity: medium
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-11973 camel: Netty enables Java deserialization by default which could leed to remote code execution
bugzilla·2020-06-18·CVSS 9.8
CVE-2020-11973 [CRITICAL] CVE-2020-11973 camel: Netty enables Java deserialization by default which could leed to remote code execution
CVE-2020-11973 camel: Netty enables Java deserialization by default which could leed to remote code execution
Apache Camel Netty enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0.
References:
http://www.openwall.com/lists/oss-security/2020/05/14/9
https://camel.apache.org/security/CVE-2020-11973.html
Discussion:
This vulnerability is out of security support scope for the following products:
* Red Hat JBoss Fuse 6
Please refer to https://access.redhat.com/support/policy/updates/jboss_notes for more details
---
Statement:
Red Hat JBoss Fuse 6 and Red Hat Fuse 7 distribute camel with the affected `camel-netty` component. However both Fuse 6 and Fus
arXiv
An In-depth Study of Java Deserialization Remote-Code Execution Exploits and Vulnerabilities
arxiv_fulltext·2022-08-17
An In-depth Study of Java Deserialization Remote-Code Execution Exploits and Vulnerabilities
An In-depth Study of Java Deserialization Remote-Code Execution Exploits and Vulnerabilities
[Imen Sayar]Imen Sayar^
[email protected]
University of Toulouse
Blagnac
France
31070
^ Part of this research was conducted when Imen Sayar was at the University of Luxembourg
[Alexandre Bartel]Alexandre Bartel^*
[email protected]
Umeå University
MIT-Huset
Umeå
Sweden
^*Part of this research was conducted when Alexandre Bartel was at the University of Luxembourg and the University of Copenhagen.
Eric Bodden
[email protected]
Paderborn University
Paderborn
Germany
Yves Le Traon
[email protected]
University of Luxembourg
6, rue Richard Coudenhove-Kalergi
Kirchberg Campus
Luxembourg
L-1359
## Abstract
Nowadays, an increasing number of applications uses deserializatio
http://www.openwall.com/lists/oss-security/2020/05/14/9https://camel.apache.org/security/CVE-2020-11973.htmlhttps://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttp://www.openwall.com/lists/oss-security/2020/05/14/9https://camel.apache.org/security/CVE-2020-11973.htmlhttps://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.html
2020-05-14
Published