ZeroHour

CVE-2020-11973

CVSS 3.1
9.8 critical
EPSS
7%p93
Published
()
Modified
Description

Apache Camel Netty enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0.

Vendors
apacheoracle
Products
camel, communications diameter signaling router, enterprise manager base platform, flexcube private banking
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.