QID 981440
QID 981440: Java (maven) Security Update for org.apache.camel:camel-servlet (GHSA-26v6-w6fw-rh94)
Apache Camel 2.6.x through 2.14.x, 2.15.x before 2.15.5, and 2.16.x before 2.16.1, when using (1) camel-jetty or (2) camel-servlet as a consumer in Camel routes, allow remote attackers to execute arbitrary commands via a crafted serialized Java object in an HTTP request.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-26v6-w6fw-rh94 for updates pertaining to this vulnerability.
Vendor References
- GHSA-26v6-w6fw-rh94 -
github.com/advisories/GHSA-26v6-w6fw-rh94
CVEs related to QID 981440
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-26v6-w6fw-rh94 | org.apache.camel:camel-jetty |
|
|
| GHSA-26v6-w6fw-rh94 | org.apache.camel:camel-servlet |
|