cbcvebase.
CVE-2020-11973
published 2020-05-14

CVE-2020-11973: Apache Camel Netty enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
Apache Camel Netty enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0.

Affected

8 ranges
VendorProductVersion rangeFixed in
apachecamel
apachecamel2.22.0 – 2.25.0
apachecamel3.0.0 – 3.1.0
oraclecommunications_diameter_signaling_router8.0.0 – 8.5.0
oracleenterprise_manager_base_platform
oracleenterprise_manager_base_platform
oracleflexcube_private_banking
oracleflexcube_private_banking