CVE-2020-11973
Summary
| CVE | CVE-2020-11973 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-05-14 17:15:00 UTC |
| Updated | 2022-10-05 20:53:00 UTC |
| Description | Apache Camel Netty enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| oss-security - [SECURITY] New security advisory CVE-2020-11973 released for Apache
Camel |
MLIST |
www.openwall.com |
Mailing List, Third Party Advisory |
| Apache Camel Security Advisory - CVE-2020-11973 - Apache Camel |
MISC |
camel.apache.org |
Vendor Advisory |
| Oracle Critical Patch Update Advisory - October 2020 |
MISC |
www.oracle.com |
Third Party Advisory |
| Oracle Critical Patch Update Advisory - July 2021 |
N/A |
www.oracle.com |
|
| Oracle Critical Patch Update Advisory - April 2021 |
MISC |
www.oracle.com |
|
| Oracle Critical Patch Update Advisory - January 2021 |
MISC |
www.oracle.com |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 982250 Java (maven) Security Update for org.apache.camel:camel-netty (GHSA-h79p-32mx-fjj9)