CVE-2020-11972
Summary
| CVE | CVE-2020-11972 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-05-14 17:15:00 UTC |
| Updated | 2021-03-15 22:15:00 UTC |
| Description | Apache Camel RabbitMQ enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Apache Camel Security Advisory - CVE-2020-11972 - Apache Camel |
MISC |
camel.apache.org |
Vendor Advisory |
| Oracle Critical Patch Update Advisory - October 2020 |
MISC |
www.oracle.com |
Third Party Advisory |
| oss-security - [SECURITY] New security advisory CVE-2020-11972 released for Apache
Camel |
MLIST |
www.openwall.com |
Mailing List, Third Party Advisory |
| oss-security - Re: [SECURITY] New security advisory CVE-2020-11972 released for
Apache Camel |
MLIST |
www.openwall.com |
Mailing List, Third Party Advisory |
| Oracle Critical Patch Update Advisory - January 2021 |
MISC |
www.oracle.com |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 982411 Java (maven) Security Update for org.apache.camel:camel-rabbitmq (GHSA-2x6r-7427-95cm)