CVE-2017-12633

Severity CVSS v4.0:
Pending analysis
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
15/11/2017
Last modified:
20/04/2025

Description

The camel-hessian component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability. De-serializing untrusted data can lead to security flaws.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:camel:*:*:*:*:*:*:*:* 2.0.0 (including) 2.19.4 (excluding)
cpe:2.3:a:apache:camel:*:*:*:*:*:*:*:* 2.20.0 (including) 2.20.1 (excluding)